It was obviously wrong to be the creepy sexist.
In the abstract sense, it is wrong to invade privacy.
But then, if in your invasion of privacy you uncover a wrongdoing, the right thing to do is report it.
It would be wrong to read the CFO's email inbox, and probably illegal. But then if you uncover they are committing fraud, you need to report it to police, as well as confess your own crime.
Unfortunately, there's never easy rules for these things.
>In the abstract sense, it is wrong to invade privacy.
You have no real expectation of privacy when using company owned equipment. This was almost certainly spelled out to the employee in question in the acceptable use policy he agreed to upon being hired. Companies have to operate this way so they can investigate computers if compelled to by court or law, and so they can recover important information off computers when the user exits the company.
If he was using a BYOD computer I'd have a different opinion on the matter.
I don't know, but I imagine that such considerations could easily extend to your password.
Btw, how did the sysop know that what he recovered was the actual password? I mean, it's unlikely, but at least theoretically possible that it was a false positive. The password hashes in those days were pretty weak... Just a thought; I don't think it realistically was a false positive.
As far as it being the actual password, a false positive AND the fact he had been creeping on a coworker at the same time seems extraordinarily unlikely to me.
Acceptable use is cracking passwords in an investigation with just cause.
Acceptable use is a script to automate the checking of weak passwords, and notify users.
Unacceptable use is an admin browsing cracked passwords, without just cause.
I personally think acting on the information obtained afterwards is acceptable, but some would disagree.
Remember even in some courts, evidence obtained by police illegally cannot be submitted for trial.
I maintain these moral problems are hard ones.
Ultimately, I think it's a case-by-case on this type of thing.
Btw, I find it very interesting that e.g. most EU courts will consider "tampered-with" evidence, but obviously take into account that it may have been tampered with and so accord it much less weight than "pristine" evidence. Whereas US courts will[0] absolutely throw out anything that's shown to be even mildly "tampered-with". I don't know what the right answer is, but it's an interesting question to ponder.
[0] Maybe this is wrong; I'm not a US-ian, so I may not have perfect insight into the court system :|.
It's not obvious as we haven't heard his side of the story.