Not like this…

The data box system got a new look. And with that they also dropped the CAPTCHA verification on login. My primary goal was to send my tax return, but I had an expired password. So: log in, change it, send. Except... I generated a password in my password manager, entered it in the form, and saw: Password must be a maximum of 32 characters. I don't get it, but fine. I shortened it, entered it again, and this time saw: Password contains invalid characters.

I genuinely don't know... I generated a third one, made sure the special characters weren't too exotic... and entered it. Success! The password meets the requirements of Decree 194/2009 Sb.

A few things puzzle me: why do data boxes — a system certainly classified as CII — have their own decree governing passwords and usernames, when such things are already covered by the Cyber Security Act and its implementing regulation. Why not make life easier and adopt what applies to other systems instead of going, or continuing to go, down their own path.

I'll see where this goes — I'll write to NÚKIB and I'm curious what they'll say.

Other Related Posts:

Collection #1

Collection #1

The biggest leak yet... of usernames and credentials.

I was curious what's actually in the largest collection of leaked data so far — Collection #1. I downloaded just under 40 GB of data. After extraction it came to just under 100 GB. I fired up Splunk and started indexing. It took almost the enti...

17th Jan 2019

Passwords, passwords... passwords

So what's the deal with passwords

I came across an article from CSIRT-MU saying that passwords are like toothbrushes — change them and don't share them. The headline is catchy enough to draw readers in. However, I came away somewhat disappointed by the article. In the section on creating passw...

8th Dec 2018