It was obviously wrong to be the creepy sexist.
In the abstract sense, it is wrong to invade privacy.
But then, if in your invasion of privacy you uncover a wrongdoing, the right thing to do is report it.
It would be wrong to read the CFO's email inbox, and probably illegal. But then if you uncover they are committing fraud, you need to report it to police, as well as confess your own crime.
Unfortunately, there's never easy rules for these things.
>In the abstract sense, it is wrong to invade privacy.
You have no real expectation of privacy when using company owned equipment. This was almost certainly spelled out to the employee in question in the acceptable use policy he agreed to upon being hired. Companies have to operate this way so they can investigate computers if compelled to by court or law, and so they can recover important information off computers when the user exits the company.
If he was using a BYOD computer I'd have a different opinion on the matter.
Acceptable use is cracking passwords in an investigation with just cause.
Acceptable use is a script to automate the checking of weak passwords, and notify users.
Unacceptable use is an admin browsing cracked passwords, without just cause.
I personally think acting on the information obtained afterwards is acceptable, but some would disagree.
Remember even in some courts, evidence obtained by police illegally cannot be submitted for trial.
I maintain these moral problems are hard ones.
I don't know, but I imagine that such considerations could easily extend to your password.
Btw, how did the sysop know that what he recovered was the actual password? I mean, it's unlikely, but at least theoretically possible that it was a false positive. The password hashes in those days were pretty weak... Just a thought; I don't think it realistically was a false positive.
As far as it being the actual password, a false positive AND the fact he had been creeping on a coworker at the same time seems extraordinarily unlikely to me.
It's not obvious as we haven't heard his side of the story.
Ultimately, I think it's a case-by-case on this type of thing.
Btw, I find it very interesting that e.g. most EU courts will consider "tampered-with" evidence, but obviously take into account that it may have been tampered with and so accord it much less weight than "pristine" evidence. Whereas US courts will[0] absolutely throw out anything that's shown to be even mildly "tampered-with". I don't know what the right answer is, but it's an interesting question to ponder.
[0] Maybe this is wrong; I'm not a US-ian, so I may not have perfect insight into the court system :|.
"Don't be snarky."
So don't be so arrogant about someone being "creepy" when they are not mentioned as doing anything specific in public...
I agree with this. Everyone deserves due process.
It sounds in this situation like they got their due process. (HR didn't fire them based on the password report, but rather used diligence and due process to investigate/corroborate and only then terminate them.)
Browser and search history, email passwords, diaries, and a list of medical professionals that I can contact to vouch for your mental stability should suffice.
We will reach out in the next few days to conduct a character assessment review. Thank you for your cooperation!
If you have any questions, do not hesitate to fill out a form with the Health and Safety Commission offices. Our hours are 10 AM to 3 PM every other Tuesday of every other month.
Remember, your health and safety is important to us.