If you like wild speculation, it is likely that the block key is large enough to provide adequate security, and that it is stored locally but encrypted with a data encryption method like RSA. The password for this might be as simple as a 4 digit pin, but thats irrelevant because the encrypted encryption key would be the first data wiped in the event of a data breech. If you're really paranoid, you could store a larger key on the network. Rebooting the device would then require network access, but it protects you against someone removing your compact flash and reading it directly.
Obviously backup files are not encrypted, or they wouldn't be very useful. If they are encrypted, it will only be as strong as the user specified password, or key stored on MobileMe.