Currently its not clear to users what kind of hardware is protecting the master key. Usually TEE or a separate secure element (e.g. Pixel's Titan Security Chip or Apple's Secure Enclave).
It would be great if that could be shown in the application somewhere.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Agreed, and I want to be careful to show the truth rather than a reassuring label. Today the honest answer is the same on both platforms: software keys live in the app's own encrypted storage, and card-backed keys live on the hardware card. No key currently sits in the TEE, StrongBox, or the Secure Enclave, so the app will not claim one does. What I have put on the Android 4.3.0 and iOS 8.3.0 roster is a row in Key Detail that states plainly which of those two protections applies to each key. If hardware-keystore-backed keys ever land (see the other thread on that), the row is where that status would appear.
NorseHorse
-----BEGIN PGP SIGNATURE-----
Comment: PGPony - PGPony.app
wnUEARYIAB0Fgmp8yUcWIQSgy8j2WqzlbxxbdndT+XmOSRneYgAKCRBT+XmOSRne
Yu2QAP9HsksKXn3Js8ZgIXPxBtur+4nioHvNCtx4yuMycVkEzQEA3yIJllC3a6Fc
URRKYtKo5qax5FVNxdUO7KCjIrbd2wE=
=dcl0
-----END PGP SIGNATURE-----