Essay
The Encryption Paradox in Cloud Backup: Who Really Holds the Key?
Zero-knowledge promises are easy to make. The sharing feature is where they unravel.

In today’s data-driven world, many cloud backup companies proudly claim to offer “zero-knowledge encryption.”
That is, your data is encrypted before it leaves your device and can only be decrypted by you — with a key that only you possess.
This is a compelling promise, and for those who value privacy, it’s often the main reason to choose such a service.
But here’s where things get murky.
Some of these very same companies also offer a file sharing feature, allowing you to share your backed-up content with others. And not just the file itself — but a version they can actually view.
That raises a very important question:
If only you have the encryption key, how can anyone else view the data unless you manually give them the key — or the company has it too?
It’s a matter of common sense and cryptographic logic. If the company truly cannot access your encryption key, then it cannot decrypt your data. Therefore, it cannot prepare it for sharing in a readable format unless:
- You decrypt the file yourself and send the readable version, or
- The company does have access to your key — despite claiming otherwise.
The more troubling implication is the second one. If you are able to share readable data from within the backup platform without explicitly sharing your key, then it suggests the service has the capability to decrypt it. That undermines the very principle of end-to-end encryption.
The Questions We Should Be Asking
So next time you're evaluating a “zero-knowledge” backup solution with a sharing feature, ask the tough questions:
- How is the shared data decrypted?
- Does the recipient need my encryption key?
- If not, how can they view it?
- Where exactly is the key stored — and who controls it?
Transparency Matters
In the age of data breaches and digital surveillance, encryption isn't just a feature — it's a promise. And that promise is only as strong as the company’s architecture and honesty.
If your data can be shared without sharing your key, it’s time to question who really holds the keys.
A Question for You
Have you experienced this situation? Did you raise these questions to your backup provider?
When a service offers end-to-end encryption and also file sharing, it raises important questions about how data access works under the hood. As Bruce Schneier has emphasized, “Security is not a product, but a process.” True encryption is only as strong as the control over the key.
Want more essays on ownership, privacy, and building products that age well?
Browse all writings