@whitequark Doesn't tarsnap provide the entire encryption layer out of the box, in such a way that not even the provider has access to your encryption keys?
(So if you're someone who can't roll their own encrypt-before-sync layer, tarsnap takes care of that for you)