Earlier quoted context omitted.
The keys in advanced protection are derived from your device passcodes, your macOS user password and a recovery key. You'll notice you have to approve from one of your devices to use iCloud web or add a new device. The deviation function takes a while to run and depends on the secure enclave, but you still probably want to avoid 4-digit passcodes.
They are, but they also must be encrypted n separate times where n is the number of signed in devices. Mac iPad iPhone Recovery Key Each of the above would have a separate uniquely encrypted device backup key as a result of the derivation function. I can change the password on any of those (or regenerate the recovery key) without a full iCloud re-encryption or duplication of my iCloud data - therefore Apple must be h…
[1]: https://help.apple.com/pdf/security/en_US/apple-platform-sec...