Earlier quoted context omitted.
Ok, so: "The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID is not related to any other identifier on the device." The secure enclave must still give it's UID under some circumstances? This still does not appear to…
Unless there is a bug in their hardware implementation of AES-CCM or ( shudder ) some sort of crazy disclosure vulnerability in the APIs they provide, there is (presumably) no way to get at the UID. Even if you were to decap the chip and get at the UID physically, you still aren't any better off as it derives the actual encryption key on boot from the UID. The Secure Enclave is essentially a hardware security module,…
I'm going on and on about this because I see no way in which this problem is not down-boil-able to brute-forcing the password the user puts in.
Actually Apple admits this much! They can build a work around! What stops the three-letter-agency from building it?
There must at some point be a complex user entered passphrase if you want to be safe. This can be a fingerprint of course but there is always the 4 letter password/passphrase that is the weak point.
I could be completely wrong, so far I'm not convinced I am.