Priviy
cloud-chiffre-comparisonCOMP

Is Backblaze secure? The private key is real, and the web restore is where it leaks

Backblaze lets you set a private encryption key, which genuinely means the company cannot read your backup. But restoring through the website requires handing that key to their servers. What the documentation says, and how to avoid it.

By Eric Gerard · Editor · Priviy3 min readPhoto via Pixabay

Backblaze sits in an unusual spot: the encryption is genuine, the private key option is genuine, and yet the service is not zero-knowledge. Both halves of that sentence are true, and the difference between them lives in one specific place, the web restore.

What the encryption actually gives you

Your files are encrypted before they leave your machine and remain encrypted at rest. If you enable a private encryption key, Backblaze states that it can decrypt your files only when you supply that key.

Taken at face value that is a strong position, and it is more than several mainstream backup services offer by default. Against the threats most people actually face, a stolen laptop, a compromised account, an employee browsing storage, it holds.

Where it stops being zero-knowledge

The gap appears when you need your files back through the website.

Backblaze's own documentation explains why: to prepare a restore, you type your private key into their server. The key is held in memory rather than written to disk, and the files are decrypted there, packaged, and offered for download.

For that window, the provider holds both your encrypted data and the means to read it. A strictly zero-knowledge service never receives the key under any circumstance, which is precisely the property that gets lost here. This is not a hidden flaw and not an accusation: Backblaze publishes the explanation itself, which is more than can be said for services that simply market the word encrypted.

A person typing on a keyboard in front of two monitors, a cup beside them
A person typing on a keyboard in front of two monitors, a cup beside them

The restore path that keeps the property

There is a straightforward way to avoid the trade-off: restore through the desktop client rather than the website. The application decrypts locally on your own machine, so the key never travels.

If you set a private key specifically to keep the provider out of your files, this is the restore path that matches that intention. Test it once while everything still works. Discovering that your preferred restore method needs a step you did not expect is a bad thing to learn during an actual data loss.

Matching the tool to what you actually need

Backblaze fits if you want unlimited personal backup at a predictable price, with real encryption and a provider that documents its behaviour honestly. For most people that is the right trade.

It does not fit if your requirement is absolute: the provider must never, under any circumstance, be able to read your data. In that case you want either a service that is architecturally zero-knowledge, or client-side encryption you control before anything is uploaded. Our comparison of encrypted cloud storage services covers the first option, and what zero-knowledge encryption means sets out precisely what the term does and does not promise.

One more thing worth doing today rather than later: put the passphrase in a password manager. Backblaze states that once a private key is set there is no way to recover it, which is correct behaviour for real encryption and also means a key stored only on the machine being backed up is a key you will lose exactly when that machine dies.

The short version

The encryption is real and the private key option is real. The web restore requires giving that key to the server, so the service is not zero-knowledge in the strict sense, and Backblaze documents this rather than hiding it. Restore through the desktop client to keep the key local, store the passphrase somewhere that survives the machine, and choose a different architecture if your requirement is that the provider must never be able to read anything.

Choix éditorial
4.5 / 5

If you want client-side encryption you control → pCloud

Swiss jurisdiction, client-side encryption available as a paid add-on rather than by default. Check whether that add-on matches your threat model before committing.

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre

Frequently asked questions

Is Backblaze encrypted?
Yes. Files are encrypted before leaving your machine and stay encrypted at rest. On top of that, Backblaze offers an optional private encryption key: once you set one, the company states it can only decrypt your files when you supply that key. That is a real protection and it is more than several mainstream backup services offer by default.
So is Backblaze zero-knowledge?
Not in the strict sense, and the reason is the web restore. Backblaze's own documentation explains that preparing a restore through the website requires you to enter your private key on their server, which then decrypts your files there before packaging them for download. The key is held in memory rather than written to disk, but during that window the provider does hold both your data and the means to read it. A strictly zero-knowledge service never receives the key at all.
How do I restore without giving them my key?
Use the desktop client rather than the website. The application decrypts locally on your own machine, so the key never travels to Backblaze. If your reason for setting a private key was to keep the provider out of your files, this is the restore path that matches that intention, and it is worth testing once while everything still works rather than discovering it during an emergency.
Does that make Backblaze a bad choice?
No, and it would be dishonest to present it that way. Backblaze documents this behaviour publicly instead of hiding it, the encryption is genuine, and unlimited personal backup at its price has few equivalents. The point is to match the tool to your threat model: it is strong protection against a stolen laptop or a compromised account, and it is not the right answer if your requirement is that the provider must never be able to read your data under any circumstances.
What if I lose the private key?
Your backup becomes unreadable, and that is the intended behaviour of any real encryption. Backblaze states there is no way to recover the passphrase once it is set. Store it in a password manager before you need it, because a key that only exists on the machine you are backing up is a key you will lose exactly when that machine fails.
Choix éditorial
4.5 / 5

Get encrypted cloud storage → pCloud

Swiss-based · client-side Crypto add-on · lifetime plans

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre