So I'm working at a fairly well known call center. They've been dishonest about basically everything from the start. I'm a Cyber-Security student and they advertised it as a tech support job but it's absolutely not. They pay ok and the call center experience is applicable to help desk jobs so I rolled with it.
So here's the deal. We all (my hiring group) just applied for direct deposit on an web-application on the internal network and I noticed it's over HTTP meaning (not like I have to tell y'all) that our logins, passwords, bank routing numbers and account numbers all went across the network in plain text. It's probable (I hope) that if it went to a remote server afterwards that it was encrypted with HTTPS but who knows.
I brought up this concern with HR and no one cared at all saying they'd bring it up with the IT guy but I have 0 reason to believe they were genuine.
First, am I overreacting, and second, if not how do I escalate this concern to actually get listened to???
[link] [comments]