How do I handle this situation - I have discovered that my employer's computer systems are 100% unsecure
In doing a search for another employee online ( I knew this person previously and randomly wanted to see if there was anything interesting about them online ), I happened across a google cache of this person's login to the corporate, supposedly internal, website.
Further search of google's caches produced a list detailing the password of every employee who accesses a computer ( this is a moderately large company ).
I sat on this all day today, I have not mentioned it to anyone. I'm about as low on the corporate structure as can be; I took this job for fun, not pay. I feel that if I took this information to my manager, it would likely get to the right people, however with so many layers of management, I worry that the tale will be spun differently and I could wind up losing my job.
I am, however, somewhat close geographicly to the main corporate offices. I'm of the opinion that I should take this information to the highest possible person, and explain the situation.
I should say that late this evening I checked one of the logins, and these are valid login/password combos. I have done nothing malicious on the site, but do realize that this is essentially hacking. I doubt I would offer this information to my employers voluntarily.
So the basic question is this - what do I do now? I can not lose this job, would like to do the right thing and help them correct their holes in security, and if possible, have this come out to my advantage.
It's possible for me to take this to the corporate office as soon as Monday, so time is of the essence; I don't want to be seen as waiting on this for a long time.
Answers to possible questions to me -
This company is not a technology oriented company, only managers or higher access computers or this website at all, though more than likely I have more computer / internet knowledge than anyone at my work location.
The internet searching was done from my home computer.
My statement of having the situation end as an advantage would be along the lines of a promotion, or recognition, or possibly a brief meeting with the owner, I'm not looking to extort or hold out for money.
The company, while employing thousands, is privately held and closely managed by the founder and family.
The person whom I was orignally searching for on the internet happens to be a relative of the owner, who I knew as an aquaintance years ago.
I appreciate any advice, thank you.
Sit down with him, and start out by saying, "Frankly, sir, I found a hole in the systems and it scared me shitless. I was googling names of coworkers and google's cache let me into our corporate intranet."
posted by SpecialK at 10:52 AM on November 18, 2007