I'm confused about the Security Key for 2FA situation, since I can't find that anywhere on iOS. On the AppleID website, it mentions it, but the "learn more" link 404s[0], and the "continue on device" button errors out.
I guess they're working on rolling this feature out on the backend still.
Why would it be so hard to believe that your recovery key is hashed and salted like every other password? You can't view your key after creation, you have to regenerate it. Do I really need to pull out Wireshark to verify this for you?
Advanced data protection is explicitly removing Apple as a holder of your keys, it's not re encrypting anything, it's not new encryption. The entire process is just deleting the key that was already stored on their servers anyway. How would it be in Apple's interest to keep your recovery key after press releases and multiple warnings saying you're on your own for recovery.
https://support.apple.com/guide/profile-manager/use-a-person...