← Privacy Guides

Encryption

Encrypted backups you can actually restore

Keep three copies of what matters on two kinds of storage with one away from home, encrypt every copy, keep one offline against ransomware, and prove it works by restoring a file.

  • Low threat
  • Time 2 hours, then a few minutes a month
  • Difficulty Moderate
  • Last verified against restic 0.19.1, BorgBackup 1.4.5

What this protects, and what it doesn't

Protects

  • Against losing a phone or laptop, a dead disk, theft or fire: another copy exists elsewhere.
  • Against ransomware and accidental deletion: an offline copy cannot be encrypted or erased by software on your computer.
  • Against a backup that leaks: encrypted copies are unreadable without your key or passphrase.

Does not protect

  • A backup you have never restored. Until you test it, you do not know it works.
  • Losing the encryption passphrase or key. Without it, an encrypted backup cannot be recovered by anyone, including you.
  • Files that were already damaged or encrypted before the backup ran, if you keep only the latest version.
  • Data in services you do not back up yourself, such as messages kept only on a server.

Prerequisites

  • An external drive with enough space, ideally two.
  • For the phone: an Apple or Google account with two-factor sign-in.
  • A password manager or paper to record backup passphrases and recovery keys.

Step by step

  1. Plan three copies, two media, one away from home

    The US-CERT paper Data Backup Options (published by CISA) gives the 3-2-1 rule: keep 3 copies of any important file (the original and 2 backups), on 2 different types of storage, with 1 copy stored offsite, outside your home or office.

    A simple version: the files on your computer, an encrypted external drive at home, and an encrypted cloud backup or a second drive kept at a relative's or at work.

  2. List what you cannot afford to lose

    Photos and documents first, then the things that unlock everything else:

    • two-factor recovery codes for your e-mail and main accounts;
    • an encrypted export of your password manager (for example Bitwarden's encrypted .json export, or a copy of your KeePassXC .kdbx file);
    • recovery keys for full-disk encryption.

    Never put a plaintext password export in a backup.

  3. iPhone: turn on Advanced Data Protection

    With Advanced Data Protection, most iCloud data, including iCloud Backup, Photos and Notes, is end-to-end encrypted so Apple cannot read it.

    Update the device first. Then open Settings, tap your name, iCloud, Advanced Data Protection, Turn on Advanced Data Protection, and follow the prompts. You need two-factor authentication, a device passcode, and a recovery contact or recovery key. Store the recovery key with your other recovery details: Apple cannot recover the data for you.

  4. Android: check the backup is on

    Google says some backup data is end-to-end encrypted with your device's screen lock PIN, pattern or password; photos and videos in Google Photos are not encrypted by the screen lock. Make sure the phone has a screen lock, then open Settings, Google, All services, and under Backup and restore tap Backup, then Back up now.

  5. Computer: back up to an encrypted drive

    Use your system's backup tool (Time Machine on a Mac, File History or a similar tool on Windows, or your Linux distribution's backup app) with a drive that is itself encrypted. The full-disk encryption guide covers FileVault, BitLocker and LUKS.

  6. For technical users: restic or Borg

    restic and BorgBackup make encrypted, deduplicated backups to a drive or a remote server. With restic (examples from its documentation):

    restic init --repo /srv/restic-repo
    restic -r /srv/restic-repo backup /home/user/work.txt
    restic -r /srv/restic-repo check

    restic asks for a repository password; without it the data cannot be recovered. With Borg 1.4, borg init --encryption=repokey /path/to/repo creates an encrypted repository, and the documentation says to back up the key separately with borg key export /path/to/repo key-backup, because the repository is inaccessible without the key and its passphrase.

  7. Keep one copy offline

    CISA's #StopRansomware Guide recommends offline, encrypted backups of critical data. Ransomware encrypts every drive it can reach, including a backup drive that stays plugged in. Plug the external drive in for the backup, then unplug it and keep it away from the computer.

  8. Restore a file to prove it works

    The same CISA guide says to test backups regularly. Once now and then every few months, pick a real file and restore it to a different folder, then open it. On a new phone, restore from the backup before you wipe the old one.

    With restic, the snapshot ID is printed after each backup (for example snapshot 79766175 saved):

    restic -r /srv/restic-repo restore 79766175 --target /tmp/restore

    With Borg, borg extract /path/to/repo::Monday extracts the archive named Monday into the current folder.

Common mistakes

  • A single backup drive that stays plugged in all the time.
  • Never restoring anything, then finding out the backup was empty or unreadable.
  • Losing the encryption passphrase or recovery key, or storing it only inside the backup it unlocks.
  • Putting a plaintext password export or recovery codes in an unencrypted cloud folder.
  • Keeping only the latest version, so a file that was damaged a week ago is damaged in every copy.

Going further

If your threat model is Medium or High, encrypt the offsite copy with a key the storage provider never sees (restic and Borg do this), keep the offline drive somewhere other than your home, and check where your phone and cloud backups can be accessed from: a seized or compromised account can expose a backup even if the device is safe.