Apple's Secure Enclave locks down user data on iPhone and iPad, including the data for Touch ID. Recently, a hacker known as xerub posted a "decryption key" for the Secure Enclave Processor (SEP) firmware:
That's led to a lot of miscommunication, misunderstanding, and misreporting about what exactly it means in terms of iPhone and iPad security. Here's the deal:
Imagine the Secure Enclave as a vault. Apple hung a big, dark curtain over it to prevent anyone from even seeing the vault. Now, that curtain has been opened and people can see the vault. The vault, however, is still locked as securely as ever. No one has broken into it and no one has even gotten any closer to breaking into it.
Technically speaking, Apple encrypted the SEP firmware to obfuscate it so people couldn't easily poke around inside. That included security researchers, like those participating in Apple's bug bounty program. Now they can.
It was an additional but very superficial layer of protection. While many deride security-through-obscurity, "defensive in depth" — a multi-layered approach — is still a best-practice and making anything even a little bit harder to defeat makes it a little bit harder to defeat.
Philosophy aside, it's my understanding that the encryption key wasn't used to protect any user data or anything beyond obscuring the SEP. And absolutely no user data was or could be exposed through the leaked encryption key.
In other words, it's something to be informed about but not overly concerned with. SEP remains as secure as ever.
iPhone XS + iPhone XS Max