Maybe they assume that a 10-number password is likely to be a phone number, and so constrain the three most significant numbers to just valid US area codes. Add in other rules, like the fourth digit never being a zero, etc...and the space is pared down quite a bit.