It’s weird to me that in this instance the software can withstand an “attacker” having the device. I see this adage when reading about social engineering, That once the person has the device, they can take control of it. Ofc that doesn’t mean they can read all the data but yeah this is something I’ve seen a few times.