No, it's more like devices should consider security holistically and only offer an API that is secure. Hacker News doesn't allow any users to edit any other's comment. Is that putting all users in jail because we don't have a capability which is technically possible?
>I wonder how an attacker could get physical access to a machine, disassemble it and flash without getting detected.
Just because an attack may be niche it doesn't mean that the vulnerability should be ignored. Some customers like businesses can be extra paranoid of attacks like these and have concerns about these attacks.
>why not just grab the drive?
Because the drive should be encrypted.