The client could be open source; indeed the network protocol might even be simple. The client distribution or even implementation might be handled by third party. If for commercial reasons the provider wants a fancy shell and doesn't trust the open source or third party for that, they might consider a locally-untrusted (and possibly even remotely run) GUI that is a frontend for your local (trusted, open-source) backup engine.
I believe you can architect a solution such that it's easy enough to get a third party (or yourself) to verify it is safe and private, even in the face of a hostile backup provider (or more realistically, a backup provider that's met an opportunistic law enforcement agency waving a sternly worded letter).
If enough parties collude, they can still gain access to your data, but at that point I'm pretty sure the backups won't be the weakest link anymore.
I mean, you're still running an OS, and compiling with a compiler, installing and running software from a package distributor, and using a CPU with a management engine, and all those things might have backdoors too.
I believe you can architect a solution such that it's easy enough to get a third party (or yourself) to verify it is safe and private, even in the face of a hostile backup provider (or more realistically, a backup provider that's met an opportunistic law enforcement agency waving a sternly worded letter).
If enough parties collude, they can still gain access to your data, but at that point I'm pretty sure the backups won't be the weakest link anymore.
I mean, you're still running an OS, and compiling with a compiler, installing and running software from a package distributor, and using a CPU with a management engine, and all those things might have backdoors too.