The invisible flaw in my photo backup strategy
I found a flaw in my photo backup plan — the fix was simpler than I expected, and it might save your images too.
ack in 2019 I wrote a post about how I backup my photos. It’s still up — you can read the old post if you want the full history. Cameras have changed since then. So has the plan. Some of it for good reasons. Some of it because I got lazy and only noticed the gap when I sat down recently and actually mapped the whole thing out, box by box, arrow by arrow.
I shoot with a Fujifilm X-T5 now. Not the camera from that old post. Doesn’t matter much for this story — the camera changes, the anxiety about losing the images doesn’t.
The 2019 version was straightforward. Internal drive for apps only. Images live on an external drive. That drive gets copied to a second external drive. Both of those get backed up to the cloud. Three copies, two of them local, one of them not. Standard advice, and it’s still good advice. What I didn’t think hard enough about back then was the last copy. The one that’s supposed to save you when the first two don’t.
Here’s the shape of it today. Internal drive on the Mac has macOS and applications. Nothing else. No photos live there — never have, not since I set this up, and I’m glad about that every time I read a horror story about someone’s only copy of ten years of images sitting on a drive that just stopped spinning one day.
The actual photo library — everything, Lightroom catalogue included — sits on an external drive. That drive is the source. From there, backup software (I use CrashPlan) does two things automatically: copies everything to a second external drive, and copies everything to CrashPlan’s cloud storage. Both external drives stay connected all the time. Time Machine handles the internal drive separately — it’s a rebuild-the-machine backup, not a rebuild-my-life-from-scratch backup. Different job entirely.
So on paper: three copies, two media types, one offsite. Tidy. The kind of thing you’d nod at if I described it to you at a camera club meeting and think, yeah, that dude’s sorted.
Gandalf The White StorageHere’s the bit the old post didn’t have, because the old post didn’t need it — I hadn’t turned on CrashPlan’s stronger encryption option yet. CrashPlan lets you set what they call an archive key password. Once you do, your cloud backup becomes what’s called zero-knowledge — meaning CrashPlan itself can’t read your files, and more importantly, can’t recover that password for you if you lose it. Forget it, and the archive isn’t “difficult to access.” It’s gone. Not encrypted-and-annoying gone. Actually gone. You start again from zero.
I turned that on because I wanted the extra privacy. What I hadn’t thought through — properly, sitting down and drawing it out — was where that password lived. It was on the internal drive. The same drive that, along with both external drives, sits in the same house.
Think about what that means for a second. If something takes out the house — properly takes it out, not “drive failed” but “the building itself is gone” — it takes out all three local things at once: internal drive, backup drive number one, backup drive number two. The only survivor is the cloud copy. Which is exactly the copy I’d locked with a password that lived on the thing that just burned down.
Three copies. Two media types. One offsite. And a single point of failure sitting quietly underneath all of it, because the key to the safe was kept inside the house the safe was in. I hadn’t noticed. It took actually diagramming the whole setup — properly, with every connection drawn out — before it was obvious. It’s the kind of thing that’s invisible when you’re thinking in terms of “do I have enough copies” and only shows up when you ask “can I actually open the copy that’s left.”
The fix I landed on: the archive key password now lives in a password manager (1Password, for what it’s worth) that syncs to the cloud independently of the house, the Mac, and every drive attached to it. If the house is gone, the password manager isn’t — it exists as software, synced to an account, not as a physical thing sitting in a drawer.
I want to be honest about something, though, because the tidy version of this story is “I found the gap, I fixed it, roll credits.” That’s not quite true. What I actually have now is a better single point of failure, not zero single points of failure. If I lose access to the password manager itself — say, in the specific scenario where there’s a fire, everyone gets out safely, but my phone (which I’d use to get back into the password manager) doesn’t — I’ve got a genuine recovery headache. Not photo-loss-forever. Just a headache I haven’t fully worked through yet.
And that’s fine. Genuinely. I thought hard about whether to chase that scenario down to the last detail — safe deposit box, trusted third party holding a copy, the works — and decided against it. A safe deposit box costs money and solves a problem I don’t have. Handing my private key to someone outside my house is a risk I’m not willing to take for a threat I don’t think is likely enough to justify it. Theft isn’t something I plan around — nobody’s breaking into my house for hard drives. Flood isn’t credible where I live. Fire is rare enough that home insurance for it is cheap, which tells you something about how insurers rate the odds.
What I settled on is this: build for the things that are actually likely to happen, not for every combination of disaster that could theoretically stack up on top of each other. A backup strategy that tries to survive the apocalypse usually just becomes too complicated to actually maintain, and a backup strategy nobody maintains isn’t a backup strategy — it’s a false sense of security with extra steps.
You don’t need my exact setup. You need the questions my setup forced me to ask, because I got most of them wrong the first time round and only caught it by accident. Where does your data actually live — genuinely, on which physical drive — versus where you assume it lives? Are your backups actually in a different place from your originals, or just a different drive plugged into the same computer in the same room? If you’ve encrypted anything, where does the key live, and would it survive the exact disaster the backup is meant to protect you from? And when did you last actually try to restore something, rather than just trusting the little green checkmark that says the backup ran fine last night?
That last one’s the one people skip. I nearly did too.
Did you enjoy this article?
Recommend it — Standard Reader surfaces well-loved writing to more readers across the network.