Home Reviews About
Twenty of Time

How to encrypt cloud backups and stay out of reach

Cloud backups are convenient because they quietly copy your photos, documents and device data to distant servers. If a laptop disappears from a café in Melbourne or a phone dies during a trip through regional Queensland, your files can usually be restored. That convenience changes when the backup provider, an attacker, an app developer or a government agency can access the stored material.

Encryption is the practical boundary between storing a copy online and handing over a readable copy. The important distinction is who controls the keys. A provider may encrypt data while it travels to its servers and while it sits there, yet still hold the ability to decrypt it. To keep your backups genuinely out of reach, encryption needs to happen before the files leave your device.

This is often called client-side encryption, private encryption or zero-knowledge backup protection. The labels vary, and “zero knowledge” is sometimes used loosely in marketing. What matters is whether the service can recover your plaintext files without a secret that only you control.

A robust setup also accepts an uncomfortable fact: encryption cannot rescue a lost password, a stolen recovery key or an infected computer. Privacy depends on the whole chain, from the files you select to the way you create, store and test the keys. A sensible Australian household or small business can build that chain without turning every backup into a full-time IT project.

Decide what needs protection

Begin with a simple inventory rather than encrypting every byte by default. Personal documents, tax records, passport scans, health information, private photographs, password databases and business files deserve stronger protection than downloaded films or replaceable application data. Separating sensitive material makes the system easier to manage and reduces the damage if a key is exposed.

Think about the people and systems you are trying to keep out. Your threat model might include a cloud employee, a compromised provider account, an advertising company, a data broker, a thief with your laptop or an attacker demanding payment for your files. It might also include lawful access requests. Encryption protects content from many of these parties, but it does not necessarily hide account details, file sizes, upload times or the fact that a backup exists.

Australian privacy law adds useful context without solving the technical problem. The Privacy Act and the Australian Privacy Principles place obligations on many organisations, and the Office of the Australian Information Commissioner can investigate privacy complaints. Those rules do not mean a mainstream backup provider cannot read your files. A company’s policy, jurisdiction and technical design matter as much as its Australian-facing privacy statement.

A practical split is to leave ordinary device backups with a reputable provider while putting high-risk files into a separately encrypted vault. That approach is less painful than trying to redesign every phone and computer at once.

Encrypt before the upload

The strongest general method is to encrypt files locally, before synchronisation begins. A backup application then sees encrypted archives rather than readable documents. Even if the provider’s storage account is breached, an intruder receives ciphertext and must still defeat your password or encryption key.

Tools such as Cryptomator can create an encrypted vault that works with common cloud drives. Restic, BorgBackup and similar backup utilities can encrypt repositories before sending them to remote storage. Some commercial backup platforms offer end-to-end encryption, though you should verify whether it applies to every backup type and whether the company retains a recovery key.

This distinction matters with services that advertise encrypted storage. Transport encryption protects the connection between your device and the server. Server-side encryption protects the disk or storage system. Both are valuable, but the provider may control the decryption keys. Client-side encryption means your device performs the final encryption step and the provider receives no usable plaintext.

The privacy risks of cloud-connected baby monitors show why this boundary matters beyond file storage. A camera feed, microphone recording or household image can be exposed through a weak account, a vendor breach or excessive internal access. A locally encrypted archive cannot stop a live device from sending data, but it can protect recorded material once it is packaged for backup.

Choose a key you can actually keep

A password-based vault is only as strong as its password. Use a long, unique passphrase made from several unrelated words, or generate a random password with a reputable password manager. Do not recycle the password used for your email, Apple or Google account. If an attacker obtains that password elsewhere, the encrypted backup becomes a much easier target.

For higher-value archives, use a randomly generated encryption key and store it separately from the cloud account. A printed recovery code in a locked home safe can be sensible. An encrypted USB drive stored with important documents may provide a second copy. A trusted relative or executor can hold sealed recovery instructions, provided they cannot access the files without the key.

Do not rely on memory alone for a key that you may need after a decade. Keep at least two offline copies in different physical locations, and label them without exposing the secret to casual visitors. A fireproof safe in Brisbane does not protect against every event, while a second copy at a family member’s home in Adelaide protects against a single-household disaster.

Multi-factor authentication still matters. It protects the cloud account that stores the encrypted archive, even though it does not replace file encryption. Prefer an authenticator app or hardware security key over SMS where practical. An attacker who takes over the storage account could delete your backup, replace files or block access even if the contents remain unreadable.

Pick storage with a clear privacy model

Provider selection should start with the encryption architecture, not the size of the free plan. Read whether the service supports user-held keys, whether recovery keys are retained, whether file names are encrypted and whether support staff can reset access. A company that promises account recovery may necessarily possess a pathway around your privacy.

Data location also deserves careful reading. A server in an AWS or Microsoft data centre in Sydney is physically closer to an Australian customer, which can improve performance and help with some contractual requirements. It does not automatically make the data immune from overseas ownership, foreign legal demands or provider access. Jurisdiction, corporate structure and the terms of service still matter.

For an NBN household, upload speed can make the first encrypted backup surprisingly slow. Schedule the initial transfer overnight or during an uncapped period, then use incremental backups so only changed blocks are sent. People in remote areas or on mobile broadband may need to seed an encrypted archive using a local drive before relying on ongoing synchronisation.

Be wary of unlimited storage offers and apps that demand broad access to your entire device. A backup client should have a clear reason for each permission. On a phone, disable automatic inclusion of sensitive folders if you are placing those files in a separate encrypted vault. Convenience is fair dinkum useful, but it should not silently expand the amount of information leaving your control.

Build a backup routine that survives mistakes

Encryption works best as part of the 3-2-1 backup pattern: keep three copies of important data, on two different types of storage, with one copy off-site. The encrypted cloud repository can serve as the off-site copy. A local external drive gives you faster recovery, while the original device remains a third copy until it fails or is wiped.

Use versioning and immutable retention where available. Version history helps recover a document that was accidentally overwritten. Immutability makes it harder for ransomware to encrypt every connected backup immediately. Neither feature is a substitute for encryption, and both may increase storage costs, so set a retention period that matches the value of the data.

Test restoration at set intervals. Open a sample of documents, restore a photograph, check that file names and dates survived, and confirm that the key works on a separate machine. A backup that has never been restored is an assumption, not evidence. Test after changing software, moving providers or replacing a computer.

Sensitive data can arrive through unexpected channels. The data trail left by online therapy platforms illustrates how intimate information may be created in an app, exported into email or stored in a phone backup. Decide where downloaded reports, appointment records and notes should live before automatic device backup copies them to a general account.

Protect the devices before they create backups

Pre-upload encryption cannot protect a file while it is open on an infected computer. Malware can capture a password, read documents before encryption or alter the backup process. Keep operating systems and backup software updated, use a screen lock, and remove old applications that no longer receive security patches.

Full-disk encryption protects a lost laptop or phone when it is powered off. Modern iPhones, Android devices, Windows PCs and Macs generally provide strong built-in options, though the protection depends on a solid device passcode and secure account recovery. A short four-digit PIN is a poor companion for valuable files.

Separate everyday browsing from the machine that holds your most important archive when practical. A dedicated backup computer, a restricted user account or an encrypted external drive that is disconnected after use can reduce exposure. Automatic mounting is convenient, but ransomware benefits from every always-connected destination it can find.

Review shared links and synced folders as carefully as the main vault. Encryption may protect the repository while a document is being stored, but a public sharing link can give someone the plaintext. Remove old links, inspect collaborators and disable automatic sharing from photo or document applications.

Plan for recovery, loss and succession

The hardest part of private backup is often recovery after a death, theft or serious accident. Decide who needs access and under what conditions. A sole trader in Perth may need a business partner to recover invoices, while a family may want an executor to access insurance records without seeing every personal photograph.

Write down the location of the encryption key without writing the key itself in an ordinary note. Include the name of the software, the account email, the device needed for restoration and the date of the last successful test. Store these instructions offline or in a separately protected password-manager emergency feature.

Check provider terms before depending on a service for legal or business records. A subscription may be cancelled after a missed payment, an account may be closed after prolonged inactivity, or a provider may change its encryption design. Keep an independent local copy and export your repository in a format that another compatible tool can read.

Physical privacy is part of the same picture. The privacy implications of body cameras on public transit guards show how recorded information can follow people through public spaces and institutional systems. Encrypting your own archive cannot control every camera or database, but it can prevent your private copy from becoming another casually readable record.

Keep the system understandable

A complicated security system that nobody can operate will eventually be bypassed. Use one main encrypted vault for clearly defined sensitive material, one reliable local copy and a documented restoration process. Avoid scattering keys across random USB sticks, old email accounts and forgotten cloud folders.

Review the arrangement twice a year. Check software updates, account activity, recovery codes, storage costs and the list of people with access. Remove abandoned devices and rotate credentials after a suspected compromise. When a provider introduces a new “smart” feature, check whether it requires server-side analysis or broader access to file contents.

Start with the files that would cause the greatest harm if exposed. Install a client-side encryption tool, create a long unique passphrase, save two offline recovery copies, and restore one test file before uploading the full archive.