Yes, password rules are bullshit, but frankly bad implementations are worse, because they train users to not even TRY to get funky with their passwords.
I've encountered more than one website that requires punctuation, but doesn't allow for every punctuation mark in ASCII, let along other languages.
I've encountered sites that let you set a 20 character password, but then their login system dies with errors when you try to use it.
These fails and many more have taught me to keep it nice and simple with passwords - don't go over 10 characters, and don't get any fancier than the rules require - that way you won't get locked out!
No, that's not a great thing, but given my utter failure at getting these companies to fix their shit in the past, I can't spend my days learning what each system really allows.