That stat proves my point, not yours. Amazon's typo broke one provider's ecosystem, not replication itself. What you're really describing is concentration risk, and you can fix that without abandoning the model: encrypt before upload, hold your own keys, mirror across independent providers. Your offline drive actually makes my case. A single drive is one point of failure entirely under your control, which is worse when it quietly dies. Robustness was never cloud versus offline. It's layers. Offline is one layer, and it belongs in the same strategy, not instead of it.