While we're on the topic of computer security, let me ask about a situation I found myself in today.

My online backup service offers "default encryption" and "private encryption." In the former, the company would store your data encrypted, but you don't have to choose the key. In the latter, you choose your own key "for even greater protection." If you forget your key, your data cannot be decrypted (unless you're the NSA, I guess). Both systems use the 256-bit AES encryption. The tech support reassured me again and again that with default encryption, my data is perfectly safe, that their employees would have no access to my data. I kept asking, "But the key would have to be stored somewhere, right?" They kept avoiding answering that question. So that doesn't give me a lot of confidence. Even though I only have personal stuff, nothing of commercial or national importance, I still wonder whether using an encryption key I don't control is a gaping hole.