https://www.washingtonpost.com/archive/business/1997/09/15/t...
"He installed a program called "Crack" that automatically guesses passwords. Like most tools, it's used by both good guys and bad guys, by those who abuse computer systems and by system administrators who want to find out whether users are avoiding such easy targets as plain English words. It's even distributed by the Computer Emergency Response Team at Carnegie Mellon University.
He installed the program without telling his boss, something that he today admits was "stupid." But the program proved his point: Crack quickly guessed nearly 50 passwords of the 600 users of that system -- one belonging to a company vice president. Instead of reporting the company's security problem right away, Schwartz has said, he decided to continue testing. Again, he admits in hindsight, "stupid."
Other system administrators discovered the program and traced it back to Schwartz.
Schwartz insisted he never used the passwords for any nefarious purpose, and said he only acted because the company's lax security bugged him."