eridius is right. Apple cannot update the firmware of the backend HSM clusters without data loss. (If you believe what they say.) They literally throw the signing keys into a blender. The article refers to device firmware not the iCloud backend.
Yeah, I got confused by HSM and Secure Enclave. I still think it is crackable given it is all secured by a user’s pin which can be verified on device by software Apple controls.
Of course Apple controls the software. Apple or any manufacturer could push an update overnight that disables all encryption and transmits your data to Donald Trump or whoever they want the next time you enter your passcode. There’s exactly zero “security researcher insight” in observing that.
The question is, if you trust that iOS and iCloud work the way Apple says they do (under oath), how vulnerable are they to an adversarial cloud. They have designed a system to keep your keychain safe under these conditions.