This is after the original version, got pulled from the beta suddenly with no reason and no widely reported bugs.
The design of this irrational system only makes sense when a 3 letter agency saw it, and got FISA to compel Apple to key escrow.
How is that obvious? And how a court do this? What would be the legal basis?
Or the more common reasoning: Apple wanted to provide a method for you to restore your new iPhone from an iCloud backup without treating your Apple ID password as an encryption key.
Other avenues of gaining potentially useful data will be utilized as well. Does the FBI have access to data stored on Apple's cloud servers? What about the fingerprints of the suspect, or other methods of bioidentification?
Only the Secure Enclave has access to the UID, but only through silicon, it can't read the key bytes.
The Cellebrite rigs do use the Secure Enclave to brute force, but they're acheiving roughly 1s/guess, and the theoretical fastest is 80ms because the Secure Enclave uses PBKDF2 iterations tuned for that time.
If you have a long numeric passcode or an alphanumeric passphrase you can be confident your iPhone is secure when it's off.
I know that on an iOS device itself, if passcode attempt limits didn't exist, it takes a whole 90 milliseconds to check each passcode. That's only 10 passcode attempts a second, and if the passcode is sufficiently long, it could take years.
EDIT: removed bad math
That's why Apple is so hard on making the secure chip they use for the encryption and holding the device uid. It's really the only thing that can keep that from being within a $10k-15k budget to break a bad passcode/pin. If they aren't using a modern KDF that has memory safety, branch safety, and other defenses in it then all the above goes out the window since you can now throw some really cheap GPUs and do it in parallel at a scale that's even more insane.
Have a look at some of the GPU benchmarks for John the Ripper
In short, physics.
It's not the PIN they'd have to brute force, but the encryption key... and that's where physics comes in.
https://support.apple.com/en-ca/HT202303
EDIT: On a second reading it looks like there's a difference between the "on server" encrypted data and the "end to end" encrypted data. Backups are covered under the former but not the latter. Shame.
The fact people don't appreciate what Snowden leaked and infosec in general is as much a result of that as it is negligence or humans being 'bad'.
However, I am really curious about whether or not using iCloud Backup negates these protections. For iMessages, Apple specifically says that it does: "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages." In other words, if you use iCloud Backup, Apple specifically holds a key allowing them to decrypt your messages in your iCloud backup.
Yes, you can never be sure that your landlord has not let other people into your house. Your landlord could let the police into your house
"Did you lock the house?"
"Yes"
"Good because I left secrets on the kitchen table"
"Oh, the landlord has a key. But it's locked"
"Um, ok. It's sort of locked. It's locked, but other people can get in. All I really care about is my secrets so I guess I'll just go back and get them and find someplace else to leave them that's more 'locked'"
In the same way a file can be encrypted, yet be insecure because somebody untrustworthy has the key to decrypt it. Doesn't change the fact that on a technical level, it's encrypted.
And how secure your landlord stores your front door key.
So if your landlord is careless and/or willing to open your door to people requesting them to do so, you can assume that your landlord IS indeed an adversary.