If I was replacing the front facing FaceID complex I sure as hell would want verifiable Apple gear and it to be paired to the phone. Why would I want some random person to be able to put something in my phone's biometric authentication path?
If I was replacing the front facing FaceID complex I sure as hell would want verifiable Apple gear and it to be paired to the phone. Why would I want some random person to be able to put something in my phone's biometric authentication path?
Yes, the articles would go something like this: "WTF is wrong with Apple, did they intentionally implement 'security' in the worst possible way, by leaving the phone unencrypted and just using faceID as a lock screen?!"
That is what they'd have to do for your statement to make any sense, they'd have to leave the data unencrypted and just use a removable component as a pass or fail doorman. So the system would have always been unsecure, it would just be more obvious in this scenario.
[1] https://www.apple.com/business-docs/FaceID_Security_Guide.pd...
If you have to worry about that I most certainly would hope that you wouldn't leave your phone to a repair-shop.
Regular, run of the mill encryption you can download at every corner store can withstand attacks from nation states.
I can answer for you: these are completely unrelated to security. It is just a middle finger from Apple to anyone wanting to repair their device.
edit: typo
Reflashing serial numbers of common i2c chips is routine, and not "harder."
It basically only deters self-taught repair shop owners, without electronics background.