Yes, but if they were following best practices (and this isn't even "best practices" so much as it is "the bare minimum for anyone handling logins to any remote system") they can't know the length of a stored password.
Now, they could measure it during login, but if they were doing that they...