> OK so in the case of a "normal" lost password then how is it that it's safe on Apple's servers?
In a word, it isn't. The new password is no more nor less safe than the old one. Or are you asking about the data, not the password? Pretty much the same answer.