You've got a great backup strategy. You've got Time Machine, an offsite clone, and all your important but not sensitive files are uploaded to the cloud, on someone else's servers. Then disaster strikes. A fire takes out your family iMac and Time Machine and all the irreplaceable photos of your kids and your life together. You have backups, though, so you don't worry much. Until you remember all the photos you scanned — the ones that are now ashes — were still sitting in a folder waiting to be added to your online library. But, offsite! You rush out, grab the drive, come home, plug it in, and—error! You try everything you can to get it to mount but it's useless. Finally, you try data recovery. And then you remember: You encrypted the drive. There's no way to recover anything on it.
You've got a terrific backup strategy. You've got a Time Capsule, you make a clone, and everything gets automagically uploaded to the cloud. Then disaster strikes. There's a break-in and your MacBook and all your drives are stolen. You have an online backup, though, so you don't worry much. Until you remember all the photos you stored on that drive — photos you wouldn't want anyone to ever see. But, they must be safe, because there must be a login or something, right? RIGHT? You try to put it out of your mind until some time, a month or so later, you're browsing that subreddit, click on a pic, and your face ghosts. It's you. All of you.
When it came to backups, I wanted to make sure I was doing it right. So, I reached out to a few people I know who either work making backup software or work in IT and make a lot of backups. I wanted to know what was the best way to do it — just encrypt the drive and then start the backup, or was there more to it than that?
The answer I got was that, in some cases, there was slightly more to it, which is what I expected. Then I got something I didn't expect: a recommendation to not encrypt backups.
Now, I'm not paranoid, but my thinking for the last few years has been "encrypt everything!" I was surprised anyone, in today's environment, would suggest otherwise. So, I asked why.
The case for unencrypted backups
For some people, the ability to recover data is the most important thing. Whether that data consists of old family and baby pictures, tax returns or business records, novels written, or old POP email exchanged, it's a treasured possession and any loss would be heart-wrenching or legally troubling.
In a perfectly backed up world, it wouldn't be a concern. Everything would be copied multiple times, both in the real world and up in the cloud and the data would be safe against anything short of alien invasion.
But the world, especially the backed up one, is seldom perfect. Backup routines falter, drives fail, and not everyone is comfortable putting everything on someone else's servers. It's possible that, at some point, you'll find you need something, and that something will only exist on a drive or drives that have failed.
If those drives are unencrypted, you'll have several options for getting to the data, including ultra-expensive recovery services should what you need be valuable enough for you to consider that option. If those drives are encrypted, though, the only thing you'll be able to recover is some metal for recycling.
Data loss is what many experts in the backup business will tell you they see far more often than data theft. And, because of that, you're better off skipping encryption and setting yourself up to fail safe rather than secure.
The case for encrypted backups
For some people, the ability to protect data is the most important thing. Whether that data consists of personal and intimate photos and videos, private business records, code written or files from clients, it's an incredible responsibility and any leak would be embarrassing and potentially career-ending.
In an ideal backup situation, it wouldn't be a problem. Everything would be locked down, locally and on the cloud, and every bit of data would be secure against anything short of the rise of the machines.
But problems, especially backed up ones, aren't always ideal. Hackers, spearfishers, con-people, thieves and other bad actors are out there and, once something exists, there's potential for your system to be compromised and a drive containing your data to be stolen.
If those drives are encrypted, there's a likelihood your data will still be safe. Those without the time and resources of a nation state might effectively be unable to extract anything useful whatsoever. If those drives were unencrypted, on the other hand, your data would be easy pickings.
Data theft is what many information security experts will tell you is the growing threat. And, because of that, you're better off encrypting everything and making sure if anything fails it fails secure rather than safe.
To encrypt or not to encrypt
I asked this question on Twitter last week and the answers I got, given the tech-centric nature of my social community, isn't surprising. Immediate reactions were "encrypt all the things!". When I asked about data recovery, though, and people began to think about it, they had the same reaction I did — everything suddenly became more complicated.
Simplifying it again takes some introspection. Ultimately, is your enemy human or a machine? What concerns you more, a drive failing or the contents of that drive getting out? If someone broke into your house, are the physical items and files they could steal more valuable and sensitive than what's on your computer? If someone got a hold of your backups, is what they'd find there relationship or career ending?
Those are the types of questions you have to ask yourself before deciding if encrypted backups are the way to go for you. And there are no right or wrong answers. Only right and wrong answers for you and your family. Once you make a choice, regardless of which choice you make, try not to second guess it. Also, try to never make someone else feel guilty for the choices they made. When you're left with a broken or stolen drive, it's easy to blame yourself and others. Hindsight isn't 20/20, it's devastating.
Personally, I'm of the "encrypt everything" mindset, but that's a product of my life and my data. Your life and data might dictate a very different mindset.
The important thing is that you back up anything and everything it would hurt you to lose, and consider carefully anything that would hurt you if lost. Then make a plan that's easy to stick to, and stick to it.
Get the best of iMore in in your inbox, every day!
Rene Ritchie is one of the most respected Apple analysts in the business, reaching a combined audience of over 40 million readers a month. His YouTube channel, Vector, has over 90 thousand subscribers and 14 million views and his podcasts, including Debug, have been downloaded over 20 million times. He also regularly co-hosts MacBreak Weekly for the TWiT network and co-hosted CES Live! and Talk Mobile. Based in Montreal, Rene is a former director of product marketing, web developer, and graphic designer. He's authored several books and appeared on numerous television and radio segments to discuss Apple and the technology industry. When not working, he likes to cook, grapple, and spend time with his friends and family.
In your Scorched Earth scenario, you forgot a few things: 1) Man-eating sharks grow legs and begin devouring all coastal residents from Maine to Honolulu; 2) ALF (the real one, not the TV show one) comes down from Melmac and eats your cat; 3) the current U.S. president declares JPEG anti-American and order destruction of all such files, rendering your pix worthless anyway. Oh Rene-Dude, what you have missed!
Here is the solution you forgot. Instead of using full disk encryption. File, by file backup. It means you can recover any individual file, provided you can piece it together right. Even better, block by block encryption, like some of the Linux drivers do. Then any block without data errors can be recovered.
I really don't agree with this way of thinking. I encrypt any drive that has anything personal on it. The only drive I don't is the one I use for iTunes since that media has nothing to do with me. You really can't rely on these companies who try to get data back. I would never be able to afford their services and its not fool proof either. My main solution I use is to not rely on one backup. I have 3 for all my personal files and my iTunes library. Drives die and even time machine messes up from time to time as it did for me last month. I always have another backup I can turn to even if the first backup drive fails. Encryption or not. I don't think pushing encryption aside is a good reason to think your backups are safe. I think whoever does that is doing it wrong. Backups in general are so often done wrong or not at all. I don't mean to tell other people what to do. I just do what works for me and lets me feel safe. Its up to everyone else to find a solution that works for them.
Thank you for signing up to iMore. You will receive a verification email shortly.
There was a problem. Please refresh the page and try again.