To Report or Not To Report
I consider myself to be an ethical person. On my school's local network, I discovered a series of _HUGE_ security holes, and reported them. I was thanked for this by being suspended and having my network priveliges removed, I can no longer even log on and access the internet. I would like to point out that other than look around, nothing was confidential, I did not do anything. I did not damage any files, or anything at all malacious. They knew this.
Now, while doing a virus scan for a teacher, I noticed that the machine scanned *.PWL files. The network is run mainly on Win98 machines running NT scripts, with a Win2000 ISA Server. (....) Whenever someone logs on, windows machines makes a copy of their password on the C Drive, and its fairly easy to decrypt.
My question is, should I report this flaw or not? I can always do it from an anonymous source, but after what they did to me last time...Opinions? (Either way, I intend on keeping some Passwords so I can get on if I really need to, in case of an emergency)