Earlier quoted context omitted.
This may well be the most elegant way to solve a complex problem. It seems to me that these silly, arbitrary restrictions on password lengths and contents are far too common to explain or excuse in this way. The full list of JetBlue's password restrictions looks very much like the restrictions at a zillion other sites. The "no Q or Z" thing is strikingly weird, but its probably less harmful than the (very common) low…
How do you type your password into your telephone, something this system has to support? That's why you can't use Q and Z -- it's not on the phone.
But this is silly really, because I've never seen a case sensitive phone keypad, which is part of their complexity requirements.