But it’s still not clear how that key is derived. It’s not clear, as implemented that Apple do not hold a master key to decrypt all data (as they do currently).
In fact, if the key is randomly generated, if you have one device (as many users do) and you lose that device. Do you lose all your data? Even if you have your iCloud password?
It doesn’t make sense. It would be a massive change to how iCloud currently operates and is used. And I find this extremely unlikely.
Right now, you can browse your photos online. That functionality is going away?
There are seemingly many open questions. But given that there’s no clear statement from Apple, I’m inclined to believe that they retain the ability to decrypt all data.