iCloud backups always were encrypted based on a key derived from your iCloud account credentials, since the beginning...
iCloud backups always were encrypted based on a key derived from your iCloud account credentials, since the beginning...
Optionally encrypted: https://support.apple.com/sl-si/HT205220
FileVault too is optional: https://support.apple.com/en-us/HT204837
First party backups from Apple (iCloud/iTunes) restore a perfect replica of the phone, including app icon locations, arrangement, notifications, offloaded storage etc. I'm honestly skeptical that anyone else would be able to pull that off.
Yes, Apple has private APIs that it uses for its monopoly abuse benefit. That is why Apple's "Music" app can't be deleted from your computer ("'Music.app' can’t be modified or deleted because it’s required by macOS.") but Spotify can be deleted.
The solution is for Spotify to sue them on this specific issue and for other people to sue them similarly.
Edit: or since it is "derived" and not really password which is used for encryption -- the derived thing could well be the hashed password. We are doomed. They might as well serial number their user and use that as key then. Never mind.
Does that clear it up at all?
FYI these concepts are originated from military crypto. The foundations are solid. Implementation... well you know how that always is.... one CVE away from perfect!!
But of course, we are talking about local backups so if you have full-disk encryption or back them up to an encrypted virtual drive, you don't even need whatever encryption comes with them.