With this change, TargetURL (where credentials of storage destinations were stored in plaintext), the backups passphrases as well as JWT tokens are not stored encrypted.
The encryption key is derived from the system's motherboard serial number, or can be set manually via environment variable.