XSS discovered thousands of personal records and documents online. The files were exposed because someone used a misconfigured device acting as a personal cloud, or FTP (File Transfer Protocol) was enabled on their router. The backups are fully indexed and require no authorization to access. XSS: “When you trade security for access, things can go horribly wrong rather quickly. The files are exposed because the devices in question are acting as FTP servers, using the person’s IP or hostname as an address””]

