If you wanted to avoid potential prying eyes, you can’t backup the device over the internet to a storage location you own. You can sort of do this with photos, but it’s absolutely a kludge.
Apple is only one US law away from completely shutting down Advanced Data Protection for everyone.
The problem with this is that it's universally applicable.
Any cloud service that has end-to-end encryption today can be forced to break it if the jurisdiction in which they're based passes a law requiring it.
"So use a self-hosted open-source cloud backup system with a VPS?" Not a scalable solution. I genuinely do not believe there is a scalable solution to this problem.
All we can do is either pick the service we trust will remain safe the longest, or DIY it for ourselves and maybe those closest to us. And fight at the ballot box to end the era of ever-expanding government surveillance of everyone's digital data.
If you mean this:
> So use a self-hosted open-source cloud backup system with a VPS?
then why not? It just needs to be set up to encrypt before upload, and decrypt after download, and have some means of sharing keys to other clients. Unless I'm being dumb and missing something?
If a 3rd party can be compelled to decrypt it, it’s not e2e encrypted.
Before they do that, it is e2ee. After they do that, it is not.
There has to be an element of trust, or else the actual use case that 99.9% of users have — I lost my device and want to restore my <whatever> - can’t be met.
It’s not like there’s some great alternative solution they’re intentionally neglecting.
Like a password you memorize? Or write down on a piece of paper and store it somewhere safe?
Use iTunes backup and then upload the files from your PC to an online storage provider of your choice?
That is a solution for 2005 when the iPod wasn’t an internet connected device. In 2025 when devices are connected, performing network backups is overwhelmingly the correct answer.
That's what I do - sync it to my Mac
In the future, we might have RISC-V, but right now, we don't. You can get laptops with Intel, AMD, ARM or IBM, and that's about it. All of the chips that are fast enough to be useful are US-based (in design and manufacturing instructions, but Asia-based in physical construction).
Say you'd be more interested in something that looks/feels like it's not from the US, you are pretty much restricted to stuff that's from ODMs in Asia. But it's the same hardware from the same production facilities, running the same firmware and operating systems.
ARM HQ is in Cambridge & owned by Japan (Softbank group)
Ideally there'd be a player like Fujitsu (also an ARM licensee), they can do an entire laptop where only the manufacturing and software is not in-house (they don't have the capacity to do that AFAIK). If you then slap some coreboot (or U-Boot) and linux on it, you'd be pretty close to a much less US-attached laptop.
Maybe NitroPad[1] from Nitrokey (Germany) ?
I don't think Fujitsu Siemens make PCs/Laptops any more, only servers. But that would have been an option as their factory is in Germany.
If you're in a country where the gov is a threat to your privacy, you're in a dictatorship.
A democratic gov does not really care a lot about personal data, it only wants tax money.
A private company cares a lot about personal data because each bit of personal information is sellable to anyone interested.
How's that tax related and not caring about personal data? Does that make the UK a dictatorship?
Really? Nothing to hide?
Any practical democracy does strange stuff.
Few people think of this. More should.
The objective should be to make that as hard as possible by not putting it somewhere you make it easy for them to do so without your knowledge or without legal due process.
And that is NOT in some cloud.