This is effectively what Apple does already. The usual difficulties with asking users to make security choices don't really apply here: Physical changes to the hardware are requires, so security fatigue isn't as big a deal. Maybe you get some protection from wrench attacks by not having the authority to pair new internal hardware, but that seems like a very specialized use case...
For example, my dad used to use Androids. Without fail, he would get malware on them, he simply could not resist bypassing the security prompt to click on something he wanted to click on. Or maybe he does not understand English, or the concept of malware enough to properly heed the security warning pop up.
With iPhone, it’s not possible, so there is no worry, and no malware. Same with the hardware changes. People like my dad, or my wife, or even me who have very little interest in technology simply want to trust their device. And this device is literally the key to their life, their financials, their personal data.
All I know is my life has been made much easier by slinging Apple devices at people in my family that they simply do not have a way to mess up.
But their main motivation is likely control and profit more than safety
I don't think most users are capable of auditing their generic hardware to be sure it is free of backdoors.
Since the phone has to already be unlocked for this privilege to be granted, it can't be used to bypass authentication.
The hardware is already installed by this point, so if it's 'spying' it can do that. The user's choice has no impact on the hardware's ability to record and/or deliver information.
At best, the replacement hardware would be able to unlock the phone for the attacker at some later time. However, the cost of getting this customized unlocking device into the phone seems high given that the attacker needs physical access to the device to embed the hardware in the first place, and then again at a later time to get into the device.
If the device is enrolled in a corporate MDM, the confirmation of HW-changes could be delegated from the user to the admin, with the device working in "degraded" mode (i.e. no FaceID) until the admin approves the Repair.
Even more, large companies could contract with specific repair-companies to authorize them for their company devices and their repairs are synced into the corporate processes.
This would create a paradigm-shift in that market as repair-volume suddenly becomes more predictable ("I'll repair phones when they come in" --> "my company is the exclusive repair-center for a footprint of 10k corporate devices"), repair-companies will commit to certain performance, then drive smaller-volume contracts and individual repairs to offset the cost of such guaranteed turnaround-times, and so on...
Nobody is sneaking into my house and replacing the faceid middle of the night. This is happening to nobody you know, and nobody they know either.
The rest of us just want our $800 paper weight to work again.
Why would the camera be of consequence, though? Isn't authentication data stored in the proprietary TPM thing Apple includes in their devices?
Admittedly you might have to put the iphone on its side so you can get the charging cable in there, which means you might have to figure out how to rotate the pictures too.
Insisting on approved camera avoids making it easier for bad actors to stealthily capture's a victim's biometrics and then use a third party "camera" to replay that information and unlock the victim's phone without them being present.
Also couldn't you avoid this problem entirely be just making the dot projector use an unique pattern for each unlock attempt?
I'm pretty sure it's not. The number of people which would be targeted by this is too small to justify the additional costs. The vast majority of people which would be targeted by this are pretty much screwed anyhow since the adversary already has physical access. It's much more likely a brand protection scheme to ensure there are fewer items out there with sub-par hardware.
If apple thinks it's an issue make it clear before letting me activate it that they no longer guarantee any safety (which they don't anyway, that's the joke, you already signed that way in the user agreement).
My ISP will provide me with a router and full support. If I change the settings or flash firmware they will no longer support it. However, if I let them restore the factory firmware and config they will again support it.
It's not hard and apple's motive here is clearly maximize stock value, nothing else.
If I am not mistaken, they also disable Face ID when you replace the camera with a genuine Apple camera from a donor phone.