It’s as safe as you want it to be, if you use it properly.

One of the comments I received on my article on lessons learned from a fairly public online hacking was very concise: “That’s why the cloud is dangerous.”
I think a lot of people feel that way to varying degrees.
I strongly disagree. Using the cloud can absolutely be safe.
I also think that believing the cloud is dangerous prevents you from taking advantage of the things it can do for you — things like protecting your data.
It also ignores the fact that you’re already doing things “in the cloud” safely and have been for years.

Safety in the cloud
The so-called “cloud” is new in name only; we’ve all been using online services for decades. They’re no more dangerous now than they were then, and likely less so. The only new thing is the number of services available. If we take responsibility for our own security, using the cloud — also known as online services — can be safe and enrich our lives along the way.
What is the cloud?
I have to start by throwing away this silly term the cloud. It’s nothing more than a fancy marketing term. Ultimately, it has no real meaning.
The cloud is nothing more than online services. Seriously, that’s all it is.
Or you could say that the cloud is simply using someone else’s computer.
Services that provide data storage, enable you to communicate with others, provide applications, sell you things, or answer your technical questions all happen in the cloud.
And that’s nothing new.
Help keep it going by becoming a Patron.
The cloud is new in name only
Most people have been using online services long before anyone thought to slap the name cloud on ’em.
- Do you have an online email account like Outlook.com or Gmail? You’re keeping your email in the cloud.
- Do you use any kind of email? Email messages get from point “A” to point “B” through the cloud.
- Do you upload pictures to a photo-sharing site like Flickr, Google Photos, or Photobucket? You’re storing your photos in the cloud.
- Do you use any social media? Yup, social media lives in the cloud.
- Do you use an online backup service? You’ve been backing up to the cloud.
I want to drive home the point that this thing people are calling the cloud is nothing new. You’ve been using it already, probably for years, before that silly name was attached to it.
So let’s drop the name and all the baggage that comes with it, and call it what it really is: online services.
OK, fine. But is the cloud dangerous?
Or, put in less puffy terms: are online services dangerous?
No more so now than it’s ever been.
In fact, I’ll claim that the average online service has become safer as service providers have learned from mistakes and implemented industry best practices.1
If anything has changed at all, it’s the breadth of available online services and the number of people using them.
The fact is that any tool, when misused, can be dangerous.
Placing sensitive information in your online email account is dangerous if you don’t secure that account properly. That’s been true all along. It’s not that online email accounts are dangerous. The danger arises from using them improperly.
The same is true for any online service, be it those generating the latest buzz or those you’ve used for years.
We’re all at the mercy of service providers
At this point, many folks point out that security breaches are often the provider’s fault, or at least related to something on their end.
Many are, it’s true.
But you know what? That’s not new, either.
As long as there have been service providers, there have been mistakes, breaches, and policy screw-ups at service providers.
I’m not (not! not! not!) trying to excuse service providers for making mistakes or screwing up. Every fiber of their corporate being should work to prevent security-related errors and mitigate the impacts when they occur.
But the reality we have to accept is that ultimately, service providers are staffed by humans, and humans make mistakes. Saying mistakes should never happen is completely unrealistic.
And it’s extremely poor security planning.
Besides, when it comes to security issues, we are most often our own worst enemies.
No one can protect you from you
Let’s go back to the Mat Honan hack for a moment, which is where that “the cloud is dangerous” comment originated.
Mat didn’t lose his data because of the breaches he experienced.
Mat didn’t lose his data because of problems with the online services (though there definitely were issues).
He lost his data because he wasn’t backed up. Even if he had not been hacked, he was at high risk of losing everything anyway if he had lost his laptop or experienced a simple hard-disk failure.
If he had been backing up his data, I’m betting there wouldn’t even have been a news story.
On top of that, the hack reached as many of his accounts as it did because he had linked all of his accounts together. Mat helped the hackers get to his accounts.
No, the lesson here isn’t that online services are dangerous. The lesson here is that we have to assume responsibility for our own safety.
And I’ll say it once again: this is not new.
How to use online services safely
Using online services safely really boils down to nothing more than the guidelines we’ve all heard before.
- Back up. If it’s only in one place, it’s not backed up.
- Use strong passwords and set up and keep all account recovery information current. Use extra security, such as two-factor authentication, where supported.
- Encrypt sensitive data stored online.
- Understand the security risks of using someone else’s computer or someone else using yours.
- Understand how to use internet connections provided by others securely, especially open Wi-Fi hotspots.
- Don’t link your important accounts together in such a way that breaching one opens the door to all; use different passwords (and perhaps even unique email addresses) for each.
- Keep your software up to date, scan for malware, and all the other actions commonly listed to keep your computer safe on the internet.
All, of course, topped off with a healthy dose of common sense.
Only the part about possibly using different email addresses for different accounts is relatively new. Everything else should sound familiar.
Postscript
Mat Honan, the victim of that public hacking I mentioned at the beginning, published an update detailing how he’s recovered from his hacking.
One quote struck me: “I’m a bigger believer in cloud services than ever before.”
This is the gentleman whose experience started this discussion. While others are quick to blame the cloud, after all is said and done, he’s not one of them.
Neither am I.
Find his story at Mat Honan: How I Resurrected My Digital Life After an Epic Hacking.
Do this
You can use the cloud — online services — safely.
There’s no such thing as perfect security, and that’s true whether you keep your information securely locked away on your own computer in your bedroom or if you store it in the cloud. There’s always something that can go wrong.
Used properly, online services can even add security by providing things like additional backups, throw-away email accounts, data replication, and more.
You do have to assume responsibility for your own security, and that includes taking reasonable precautions to prevent problems and additional steps to minimize the impact should something happen.
Yes, you can avoid online services altogether (remember, that means walking away from email as well), but you’d miss out on so many of the opportunities the internet has to offer.
Rather than asking “Is the cloud dangerous?”, learn to use it safely. I believe that in the long run, you’ll be much better off for it.
I know I am.
I discuss this kind of thing every week. Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.



Before services like OneDrive and Dropbox, I used to back up my most important files by emailing them to myself, encrypted using PGP. Of course, that only was a few files but it was my introduction to cloud storage.
One thing I do is to check if a website allows a user name other than an email address. If it does, I make one up. I also check the password requirements for a site and max them out. Since I use LastPass, remembering them isn’t a problem. If two factor authentication is available, I use it.
Bottom line is anything I can do to make it harder to guess, I do it. I keep regular backups, so I am not concerned about data loss.
One other thing for US readers. Equifax, Transunion, Experian, and, another credit reporting company, Innovis, all allow individuals to sign on to their services and to lock their credit reports. Of the four, Experian charges $4.99 a month, the others are free. Users can unlock their files when necessary and then lock them again. You can also request a PIN from the IRS that is needed when filing a tax return. You will receive a new PIN each year that must be entered on your return when filing.
In 2018 there was a law passed (in the U.S.) that made all credit freezes free. They should be free at all the credit agencies. I don’t know if you’re making a distinction between a “lock” and “freeze”, but the term “lock” is used by Experian as a part of their paid security services. A credit freeze should never have a monthly charge.
A “lock” gives you control of your credit report without having to contact the credit reporting agency and takes no time to unlock or lock it.
Essentially a lock and a freeze are the same. I went back to Experian and I’m paying a little extra for additional services. To just do the lock wouldn’t cost anything.
My main point is that is another way to protect yourself in the event of a data breach. 5 years ago, I had someone attempt to file my Federal tax return. The IRS and I both agreed that it was a foreign actor as they filed the return on December 31st for that tax year, which prompted a letter from the IRS. So, I know my data is out “there” somewhere, already. I’ve taken as much action as I can to make it useless to whoever might have it.
To me the cloud is simply a marketing term for the Internet. I have always believed that one should never consider the Internet as private, whether it be email or online storage. Someone somewhere has access to whatever you are doing on the net. I would never backup my files to the Internet unless I considered them public information.
You can encrypt any information you don’t want accessible to strangers.
How Do I Encrypt a Folder?
How Do I Encrypt a File?
Aside from all of the above concerns, my reason for not using cloud storage is simply that it slows down any system. Unless you are using a top of the line speed machine you are placing an extra load on your PC. If your machine is old or has weak hardware you will be shooting yourself in the foot as far as performance goes.
I have 3 different cloud sync programs running on my computer and I haven’t noticed any lags. Any slowdowns would be due to a slow Internet connection and has little to do with the speed of the computer. Bandwidth is only significantly affected when files are being uploaded and downloaded so most of the time, just being logged into a cloud syncing site in itself has little effect on speed.
Leo stresses the importance of backups to protect your data against loss. Encryption, probably, runs a close second in protecting your data against theft.
Cryptomator: Encryption for Your Cloud Storage
Cloud? It is actually quite simple: anything not in your exclusive possession is not yours.
Trust only at your own peril.
Is “The Cloud” Safe?
Yes! Of course it is! It’s only silly ol’ us, & the way we sometimes (mis)use “The Cloud”, that can render it unsafe.
“That’s why ‘The Cloud’ is dangerous.”
Slightly reworded, I’ll actually agree with that: “That’s why The Cloud can be dangerous.”
So, take heed! And don’t be dumb when using “The Cloud”! (It’s not very “stupid-friendly,” I’m afraid.)
Driving a car is dangerous; crossing the street is dangerous. We do many things that are dangerous several times every day. We take precautions by using seatbelts, installing airbags, crossing at crosswalks and still looking for cars that might run a red light, etc. It’s the same with using the cloud. Use strong password to log in to the cloud and encrypt all your files you upload to the cloud. And use a password manager to keep track of your passwords. You can even store your encryption passwords in the password manager, so you only have to remember one password.
My dislike of what is called “the cloud” today, aside from my own perceived security issues, is the loss of “purchasing power”. What I mean by that is consumers are losing the ability to buy many useful things. I like to buy my cars and other large ticket items if I can afford to, rather than leasing. OK, I’m a control freak. My accounting software still does fine for me and it’s a 2000 version. I have been very happy with Windows 7, despite having another machine with Windows 10 on it. Eventually I will be forced to move to the other machine, but I’m fighting it. Using the cloud for applications just seems like a way that big software companies can pretend they’re selling you something, when it’s really only a short-term license. If they owned my accounting software, and decided it was time for me to upgrade, there would be an implied “or else” in the deal. They could, and probably would, stop me from using that application, as it was on a short expiration license.
Maybe I’m an anachronism, but I like to own what I can own, and oft times today’s software companies are trying to stop that. JMHO. Thanks for the great info, askleo.com.
The reason the Cloud was used to market is that you are using somebodies else’s computer for storage. Yes, just like your email is stored on their computers, any documents you store online for access by multiple computers is stored on some companies computer. The difference is that there should be even more security over documents stored, than emails stored.
Encryption is fine if you are the only one to access that document but becomes a real pain when the document is shared across the company. I have several spreadsheets on the cloud that I have password protected, but I would hate to hand access to somebody else with my password for that spreadsheet.
You should keep a copy of the document/spreadsheet on your computer and back it up as changes are made to the document/spreadsheet in the cloud.
The greatest danger to documents on the cloud is from the employees working for the company supplying the storage you are using. Much easier to hack from inside a company than it is from outside. This means that anything you do will not help since they not only have access to the documents stored but also your login data. This is normally how you get massive breaches of the cloud. This is where encryption of your documents and spreadsheets might help, as the cloud company will not have the encryption stored on your computer.
I would agree with you that you should never use your password/passphrase that you use for the cloud for anything else. Evaluate what you have stored on the cloud. Does it really have to be there? If you only access it from the same computer and never share it, maybe it does not need to be on the cloud.
The cloud (i.e., servers and data-storage systems elsewhere, to include in Russia and China) is safe. Or so Leo asserts. I disagree.
Leo and I are of different generations. I’m a math/engineering science BS/MS/Dissertation-short-of-a-PhD octogenarian, one or two generations ahead of Leo. A FORTRAN, put a-person-on-the-moon using a 2K/36K memory processor, kind-of-guy.
Everything is safe … until it isn’t. And recently Leo posted a blog telling his readers to abandon LastPass, a “secure” password manager (https://askleo.com/lastpass-breach-2022-my-recommendation/). In his estimate it was no longer trustworthy. His recommendation on the latest LastPass security breach? “It’s time to move on. The questions are, to what and how quickly?”
So how do we find out about compromises? Often second-hand and long after the fact. When it may be too late. And how do we know it’s too late? We don’t. We could become a victim long after a breach. The mumbo-jumbo, geeky explanations often released by the violated entity often tell us little to nothing.
So when using internet or cloud-based services Leo suggests that we protect ourselves. I agree wholeheartedly. But unfortunately most of us do not have the time, level of expertise, and knowledge that Leo has to be comfortable in adequately protecting ourselves. (But I do appreciate that Leo is indeed trying to educate us!)
The best advice whenever using any online or cloud-based service? Use lengthy passwords (a minimum of 16 random letters, numbers, and characters, both upper and lower case) and two-factor-authentication. Encrypt if possible. Then hope that the service provider has its security act together. And maybe, like me, minimize the use of these services unless there’s no reasonable alternative.
My current employer – I‘m still employed supporting a DOD/Space Force contract – does not allow us to use cloud services to store work-related, unclassified-but-sensitive information when logged onto its system/network. Rather, we use encrypted, password-protected external hard drives. Understandably so.
I don’t trust the cloud either, but it’s not very difficult to encrypt the files you upload to the cloud. As I said in a previous comment, encryption can be as simple as using 7Zip to encrypt files. Yes, it’s a couple of extras clicks, but it’s something anybody can do.
I just ran a test. I encrypted a 250 MB folder with a 30-character password. It took me about half a minute to encrypt it. It would take a similar amount of work to decrypt the folder. You can keep an unencrypted copy of that password somewhere safely on your computer or in a notebook or somewhere in your home. If you want a memorable password, you can use something like “Thequickbr0wnf0xjumped0verthelazylapt0p?” Memorable, but uncrackable.
I think the whole point here isn’t the technical part of the cloud. The question is WHO is the cloud? Is it Microsoft, AT&T, Samsung, Google etc. or the government? What do THEY do with all the personal information they have on hand from every internet user around the world? I think they’ve pushed us all into a corner where we can only say YES and AMEN to everything how THEY treat us as transparent people. Eat or die!
This is an argument for encryption. Email is a cloud service. Unencrypted emails are as private as postcards. Unfortunately, email encryption is difficult. I’ve done it, but it’s not practical for the average person at this point. You’d have to exchange public keys beforehand. Encrypting files you keep on the cloud is easy. It can be as simple as .zip encryption or as sophisticated as using Cryptomator of VeraCrypt which are not too difficult for the average user. As the saying goes, “Trust but verify.” When it comes to the cloud, “Trust but encrypt.”
I misspelt my cloud email address How can I change this to my correct email address to match my email I have had for 20 years?
It’s impossible to say without knowing which cloud service. It might not even be possible if they require a confirmation sent to your registered email. If that’s the case, I’d open an email with the mistaken address so that I would have a recovery email address.