InvalidError :
apertotes :
I am sure they can create a backdoor that needs physical access to the device and won't work over the internet.
How do you guarantee that? You can't. The security of the UID relies on the fact that it cannot be externally accessed for reading by any means whatsoever - short of shaving the chip and reading individual EEPROM cells with an electron attraction force microscope. Once you include a read-back path in the chip, guaranteeing that it won't be accessible through unintended paths and side-channels becomes difficult to impossible.
One possibility might be to make the read-back facility only accessible through missing balls under the BGA, requiring desoldering the BGA from the motherboard, a special jig to activate the read-back facility and extract the UID - with a risk of destroying the BGA and the UID it contains in the process. The UID extraction process would also need self-destruct capabilities to prevent thieves or other unauthorized parties from getting any significant practice out of a chip.
The process cannot be made any simpler than that to prevent abuse from authorities (if it was as simple as plugging in a USB/SD dongle or plugging into a motherboard header, there would be a high probability customs and other places would conduct wanton unwarranted searches) and also keep skilled phone thieves out - at least until the UID extraction method gets leaked or reverse-engineered. After all, theft deterrence is the other major reason behind strong hardware-backed cryptography in shiny new devices.
I did not understand much of your post. I am not versed on the how apple security works or on any kind of security. Maybe Äpple really created a no-backdoor solution. What I think is that there should be one, and maybe that means that Apple should change its design to allow authorities access to data on a phone they physically have.
About the last part of your post... Well, I simply think we are already exposed to such abuses. Judges can order searchs, can ask for financial information on you to banks and credit unions, can get info on your social security number, work history, medical history, etc. But that does not mean they are going to do it. Can a hacker do that too? Sure they can! That does not mean we should forget about digital data and get back to good old paper.
I do not get why we are all so worried about the FBI spying our emails, when they already can get almost any information they want. They can get a search warrant and read your diary!