We used to run an ad on reddit that read something like:
Your infra is on Amazon AWS and your backups are on Amazon AWS ... you're doing it wrong ..."
... and we had to stop because it made people angry.
They were quite irate and combative at the very notion that there was any non-zero risk whatsoever* at AWS.
They are not doing it wrong. What’s the threat model you’re saying people are not accounting for? eu-west-1 getting nuked?
“AWS” also isn’t a monolithic entity: for all intents and purposes AWS Backup is a separate vendor from AWS RDS, just with a unified billing and management pane.
I’d rather use that vendor, integrated with my AWS resources and managed with the same access controls, encryption, billing, etc that I use for everything else than ship it off to a random third party and maintain that connection.
Because the risk factor of multiple, isolated and separate AWS teams running different products with different infra having simultaneous large data loss incidents boils down to “nukes”.
So maybe people get irate in the same way as they might do with people who say stuff like “the cloud is a scam, why use it when you can host things on servers in a closet?”
https://docs.aws.amazon.com/AmazonS3/latest/userguide/batch-...
Also while I have heard many horror stories about suspicious account closures for many vendors, AWS at least currently seems to be on top of their game.
I fully agree with your argument, just adding colour to it
Especially because your credentials to AWS are likely stored somewhere that would also store your credentials to your separate backup vendor -- so why would two cloud vendors provide any more protection than two products within one cloud vendor?
It's clear to me how to model hardware failure, or accidental data loss. It's not clear how to model "hackers gain access to one set of credentials but not another" or "provider closes your account and won't give you your data".
At that point, if you're only in a single region, you're stuffed. Networking may be affected and you want to spin up in another region, but RDS APIs fail so you can't copy over your backups, for some reasons AMIs won't copy between regions and the R53 control plane APIs fail too, so even if you could bring up a replacement you can't update DNS anyway...
These can be planned for and mitigations put in place in advance, but that involves similar reasoning as might lead you to decide multi-cloud to be a safer option.
In general, I have 4 copies of any piece of data I care about: the machine, dropbox, backblaze, and a local external hard drive.
I lost a decade of my life data when a main hd failed, and a tb backup drive failed at the same time.
You have zero backups if they're untested.
If they're tested and separate by vendor and/or distance, if they're in an accessible medium or format, then they are different.
Life is lossy
I also keep my important passwords written down on a piece of paper in a fire safe. This includes my borg and tarsnap keys.