said by Techman21:Say I were to have a database that allowed employees to telnet into it, as long as they know the correct IP as it is not advertised on the net. Yet a guest account was left for those employees that forget their passwords. And a non employee was to access the database. That guest account is not saying come one come all and join in. If unauthorized access was still achieved by that non-employee I'm certain that a court would find a case in the favor of the company as its intention was not to allow others outside of the business access the site.
Granted that is somewhat of a poor example.
No, more like the court would not do much unless $10,000 of damage was inflicted. Then they would probably fine you for leaving personal info in the open, unsecured. Very poor example, because you would walk away just as screwed as you were when the data was stolen...