Not like this…
The data box system got a new look. And with that they also dropped the CAPTCHA verification on login. My primary goal was to send my tax return, but I had an expired password. So: log in, change it, send. Except... I generated a password in my password manager, entered it in the form, and saw: Password must be a maximum of 32 characters. I don't get it, but fine. I shortened it, entered it again, and this time saw: Password contains invalid characters.
I genuinely don't know... I generated a third one, made sure the special characters weren't too exotic... and entered it. Success! The password meets the requirements of Decree 194/2009 Sb.
A few things puzzle me: why do data boxes — a system certainly classified as CII — have their own decree governing passwords and usernames, when such things are already covered by the Cyber Security Act and its implementing regulation. Why not make life easier and adopt what applies to other systems instead of going, or continuing to go, down their own path.
I'll see where this goes — I'll write to NÚKIB and I'm curious what they'll say.