> You can encrypt and upload a copy of your Timeline from this device to your Google Account, in case you lose your device or need to switch devices.
You can recover the data after losing your device (which would be the only "end" in end to end encryption), which means that the data isn't actually E2EE, and thus Google or anyone with access to your Google account can still access it.
Your phone unlock code is typically not complex enough to withstand brute force attacks, so brute force attack resistance is added using an HSM in the datacenter (just as brute forcing the code locally is prevented using an HSM in the phone). A similar technique is also used by Signal, you can read about it here: https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
We do this at verida.io
Yes, the key management is the issue.