With an iPhone, any storage you can access with physical access is going to be encrypted. The encryption key lives in the secure enclave, which you do not have access to even with physical access, barring drastic measure like trying to take chips apart and scanning their contents, which may or may not be feasible at all.
What still may be possible is bugs and exploits, but that's up to whether you are lucky enough to have one that works against a particular phone and firmware.
If I wanted to hide an important piece of information, I guess I'd find a physically obscure and secured playce, like a hidden safe or whatnot. But I wouldn't trust crypto, no matter if the key were placed in a "secure enclave" (haha), or not.
Every phone ever sold can have its internal data read, it's not a case of if but when. This also applies to every HDD, SDD and any encryption software you may be using, it will be cracked eventually.
So, not realistically viable in 99.99% of attack scenarios.
The idea of a Secure Enclave has existed for years in the form of Chip-and-PIN bank cards. Before that HSMs are built on the same principle (a bank card I just a tiny HSM).
Of this works on the principle that it’s very hard to reverse engineer silicon, and that you can make it harder by creating silicon designs that deliberately obfuscate their purpose.
End result is a piece of hardware that very difficult to take apart with irreversible damaging it, and destroying the data in the process. The attack itself would also require an extremely high level of skill.
Ultimately no security is perfect, it’s not meant to be. Security is just meant to skew the effort-reward equation enough that no one can be bothered to break into your thing.
Citation needed.
> If I wanted to hide an important piece of information, I guess I'd find a physically obscure and secured playce [sic], like a hidden safe or whatnot.
That's just basic threat assessment. Obviously if you have a chunk of data that's really sensitive, it would be best to "air gap" it from the internet.
> But I wouldn't trust crypto, no matter if the key were placed in a "secure enclave" (haha), or not.
Please review Apple's "Apple Platform Security" document before continuing to comment. [1]
[1] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...
Just because the FBI pay $$$$ per unlock, doesn't mean the marginal cost to the supplier is $$$$, that could just be GrayKey trying to cover the $$$$$$$ they paid for an exploit, and make some profit.