Please stop doing this: https://i.imgur.com/2WeVGxK.png It's so frustrating. Early in your product lifecycle it should be painfully easy to get started and you shouldn't be worrying about this kind of security.
I don't see any issue with this? It makes sense to keep the accounts secure, and very few people will be coming up with passwords by hand; they'll be using the auto-generated ones from their browser (or from their 3rd-party password manager for the more HN-y types).
These restrictions do not add security in practice. People just add `!` or `1` as necessary to make the thing shut up. All it does is make signup harder.