mdf:
The scenario I guess I had in mind was some kind of malware that provided remote access to the server (don't know whether this is even possible). The server presumably has all the credentials for all your cloud services it is syncing. With this access, the hacker then either deletes (malicious/psychopath) or changes all the passwords on (ransom) the cloud services and the server itself.
Given I'm still working through options, I'm aiming for something that is as invulnerable as possible (if possible). Right now, to me that means something that is physically isolated from the rest of the internet. Which might only be possible with an external HDD and a bit of personal discipline, but I was wondering if there was a smarter option than that.
AWS Glacier with Vault Lock. It's write once, read many, no delete, and you can prevent any future changes to this policy. It's about as close as you can get to "read only" on the internet.
Of course, if you don't pay your bill, I assume the lot gets deleted eventually.


