Legality of decrypting passwords

Legality of decrypting passwords

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Legality of decrypting passwords onthax 06-30-2008
Posted by on June 30, 2008, 8:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I am having an argument with a coworker, who thinks it is fine to
decrypt users passwords to migrate files, as it is faster and more
convenient than having the users resetting their passwords.

I am sure this is almost never necessary, is a horrible invasion of
privacy, and quite possibly illegal.

Can anyone shed light on if this is legal or not, and if signing away
your data to the company would extend to them having the right to
decrypt your passwords?

Any legal cases would be extra useful

Cheers

Posted by Doug McIntyre on June 30, 2008, 12:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
onthax@gmail.com writes:
>I am having an argument with a coworker, who thinks it is fine to
>decrypt users passwords to migrate files, as it is faster and more
>convenient than having the users resetting their passwords.

>I am sure this is almost never necessary, is a horrible invasion of
>privacy, and quite possibly illegal.

Illegal? How so?

The servers would belong to your company. All data on them including
user account info/username/passwords/etc would belong to your
company. If you are authorized by your company to do what admin work
you need to do, ultimately you are working for your company as per
their policies. (ie. this extends to email, any and all files on the
company equipment, etc. If you don't want your company to know
anything personal, don't put anything personal on their systems).

If anything, this is a policy issue decided by the CIO or whatever
passes as such at your company. If they have authorized you to do
your work and this is necessary to do your work, then thats their
policy allowing it.

Not sure why an admin would even need a user password to do file
migrations in the first place, just do it and update whatever pointer
to where they are.

Similar ThreadsPosted
New free tool for monitoring and decrypting SSL traffic April 19, 2005, 5:15 pm
passwords October 19, 2007, 11:42 am
Hashes and Passwords May 21, 2006, 5:36 am
Win passwords - transmission to server November 27, 2005, 1:36 am
Stored passwords vanished -- is it a bug or a virus? June 17, 2005, 6:35 pm
Stored passwords vanished -- is it a bug or a virus? June 17, 2005, 6:35 pm
how to programmatically prevent passwords being saved? November 14, 2005, 11:26 am
FAQ: How can I generate good strong passwords? December 5, 2005, 5:56 pm
FAQ: How can I generate good strong passwords? December 25, 2005, 11:33 am
FAQ: How can I generate good strong passwords? January 26, 2006, 11:35 am

The site map in XML format XML site map

Contact Us | Privacy Policy