If they're actually a backup they can be a good idea. If it's a single source, then yeah, it's asking for trouble. I even backup my GitHub stuff locally because who knows what could happen.
If it's a true backup, it should be encrypted in my opinion, especially on the cloud. Then it doesn't matter since they can't see it.
Should I go into detail?
Love your profile text, by the way.
EDIT: one quick example is that I’ve lost more data by forgetting passwords than I care to admit. They’ve all been from an age where I thought it was a good idea to encrypt my secret documents, lest prying eyes get to them. Turns out the secrets would’ve been interesting to me, but are no longer accessible. I suspect this isn’t uncommon.
Many cloud storage services try to understand and then "clean up" file types they understand. If you don't believe me, upload and then download a TB or so of images, documents, music, videos, etc. Then, compare the checksums of the original and restored copies.
On top of that, there are services like Amazon Cloud Drive that have content-type restrictions.
The only reasonable litmus test I've seen in this space is "there is a cryptographic proof that some middle manager didn't screw up my backup".
Unfortunately, that means you need to manage the encryption keys somehow. Cloud storage kind of sucks.
This is a you problem. 100 percent PEBKAC.
I've been encrypting every backup, local and cloud, and plenty of other things, for probably 30 years. I've done my share of restores, and have never lost the only key to anything I later wanted back. That's true even though I have forgotten a few passwords, because I had failsafes for that situation.
This requires memorizing only three or four long passwords, which change very rarely, plus a little bit of discipline and occasionally some maintenance of your archives.
On the other hand, putting something somewhere, like some cloud service, without seeing all the implications, is a mistake that's easy to make and hard to clean up. Storing stuff in the cloud in the clear en masse is an insane thing to make into a normal part of your routine.
They were only ever "the smart thing" because they took some hassle away at the point of creating the backup.
At most they should be able to put it in RO mode to let you take it out.
Do you think the average erotic fiction writer is keeping abreast (lol) of cloud data access + integrity news?
Local hard drive + a cloud provider should give you like 99.999999% reliability
This has been my general strategy for personal data. I have also been trying to figure out if there was a reasonable way to get long-term very-cold storage (e.g. backups of family pictures). Something that would last decades just sitting in a fire-box somewhere (reasonable temps, no moisture). Been considering https://en.wikipedia.org/wiki/M-DISC, but interested to know if anyone has other ideas...
Maybe a second cloud provider would also be good. I'm going to think about this.
The average user isn't aware of this. This kind of stories usually do not emerge in mainstream, or user-exclusive spaces.
My family use a mix of Office 365, Exchange Online and Google Workspace for email, documents, etc. Add to this the required Microsoft Account for Windows logins and OneDrive.
I use a Synology NAS and they have packages to backup all these kinds of accounts, including versioning.
Even if an account is closed their files and emails live in our NAS.
If someone's life depends on anything digital, backup is a minor inconvenience or cost.
It’s not a backup when it’s the primary (and only!) copy.
Failing to proactively ban a tiny obscure account posting illegal or extremely unpopular content just sets you up for political attacks either in the form of hostile new laws or of activist groups contacting your advertisers to convince them to stop doing business with you. Outlier users are definitely potential liabilities.
And yet people never learn. Every couple of months you see someone begging for help on HN because Paypal, Stripe, Google and so on cut their access