Usually something like this is just a sanity check. 16 characters is definitely a little stingy though, but I'd wager that a very small percentage of their user's ran into this limit (mostly those pre-encrypting locally like I do), so I think we're overblowing the issue a bit.
Those character restrictions are just silly and annoying though.
But they had to make a specific decision to forbid long passwords; "lazy developer" or "silent assumption" doesn't explain the extra effort.