3 ms·
What I understand the author to be saying is that the SE will unwrap locally stored synced credentials and then encrypt them to the previously-established iClou
by md_ 3y ago
What I understand the author to be saying is that the SE will unwrap locally stored synced credentials and then encrypt them to the previously-established iCloud sync key.
It doesn't really matter if the storage of the actual wrapped keys is in the secure element or on disk, of course--what matters is if the SE exports unencrypted credentials, or if it fails to validate the identity of the key to which it encrypts credentials before exporting.
It doesn't seem from that description like it does either, but it's a bit unclear to me from the docs. Do you know?