Compare to the "firewall" approach which is crunchy on the outside but nice and soft on the inside. Snowden showed the NSA intercepting unencrypted internal comms between google's and yahoo's respective datacenters. And our IoT devices are often exploited vectors.
Interesting the Apple wouldn't even consider their own device boundary adequate. Compare to others who (used to? Still do?) keep, say, fingerprint data in the filesystem. Some people say code structure reflects organizational structure; I wonder if apple's own corporate structure (with internal inter-project secrecy, which I consider insane) lead in part to this approach: "I can't trust those other organizations writing system code to use the security features I put in so I'll consider them a kind of adversary too"