Thanks for flagging this up, this may in fact be a bug, I will need to double check the server side code, but IIRC only the username is character restricted the password can contain 'odd' characters. I do remember that I had applied this filter to the password field on the login page, and someone with an existing account couldn't log in, it seems I overlooked mistakenly adding it to the create account page too!