What security scenario would you even use as a basis here? Ridiculous...
Totally not resales negatively affecting Apples turnover.
That aftermarket car bumper? Sorry, can't use it, might come from a stolen vehicle.
Or some guy that figured it out with or without insider knowledge (which also usually means anyone can make a key for your car).
Specialized smaller shops also have the ability.
Currently there is NO WAY for me to change a screen on apple device without an annoying message or faceId issues on the 13. I cannot purchase a programming software.
Trivial solution for someone like apple.
Any phone that lets you just circumvent security by removing a part wasn't secure in the first place.
So everyone will just click "Approve" in order to get their phone back. In which case what is the point of even having trusted signatures at all ?
Pretty sure this is understandable.
Yes, in theory it might be a problem. In practice any supply chain that resulted in a significant issue like this would be easily prosecuted so let wetware systems handle the things they’re better suited to.
But the entire assumption that parts are restricted for security reasons is flawed. "Security" is done in the main SoC, the peripherals such as Face ID/Touch ID sensors should just be dumb input devices providing the face/fingerprint data to the SoC which authenticates them. There is absolutely no reason why those should be part of the chain of trust.
I went to an iPhone repair shop because my phone was boot-cycling and the repair guy basically said “yep, that’s a faulty front facing camera, stops it booting”. Then he unplugged it and the phone was able to turn on. At this stage he could even plug the camera back in and it worked… so I’m assuming it was actually an issue with the faceID signing process at boot that bricked my iPhone. The repair guy said it was really common.
He could replace everything except Face ID on the device which was a big shame as it killed the resale value (he could replace the earpiece/camera module with one that didn’t have faceID which is presumably to avoid issues with signing).
Maybe someone will make a flex cable that has it all integrated.
So the phone boot cycles if the cable is in, but if you take it out and then insert it back during boot the front camera and front speaker work but not FaceID.
I don't even have my face registered and just use a passcode for everything.