Any discussion about this is shut down. I just read an article https://www.bbc.com/news/articles/ckqxvy98x578o In the UK according to the BBC, politicians are pressing Samsung and apple to make stolen phones bricks. Samsung in response said that they have implemented several security features for this purpose. I think Samsung considers removing OEM unlocking a security feature according to the bootloader unlock hall of shame.

Intel used to do the same with their anti theft technology aka Intel theft deterrent on their classmate PCs, so students had to enter unlock codes from an IT admin every 3 months or every say 200 boots to prevent the computer from being locked at the bios level preventing it from booting an OS, and there was an update which disabled that functionality permanently. And you would be warned when you had around 50 boots left to get the unlock code.

Also in other countries like Panama, people are pressing politicians to crack down on theft and the most stolen things are wallets and phones. So by permanently locking the bootloader, manufacturers avoid as much liability worldwide as possible. Avoiding legal liability worldwide is why phone manufacturers want phones to be as locked down as possible.

Normally the codes would be downloaded automatically from a server but sometimes the server would go down due to negligence because it would be owned by the school and well, student's laptops would start getting locked and they would have to go to a specific office somewhere in the city to get an unlock code from the it admin

Normally you have to unlock the phone before unlocking the bootloader, and that is the protection.

I would think they are guessing most people's passwords are weak or something. Like a screen pattern is weak, can be broken in just 300k attempts or maybe less because people use the same patterns and people can't be bothered to use passphrases.

PIN and patterns are secure because the security module enforces rate limits, you can't brute force effectively if every attempt after the first 10 takes a minute. Biometrics can be even better against brute force (more possible combinations) but they are vulnerable to cloning.

With a 6 digit code cracking it will take close to a year on average. With your screen pattern example it's around 100 days. That's more than enough time for the owner to notice and turn on anti theft features. Maybe even for the police to find and return the phone.

I think the average person doesn't know they can use the find my phone feature on Android to lock their phone. When their phone is stolen they just get sad and call it a day and get another one. Maybe report it to police if they care in their country if police don't care, they just get another phone the day after.

I would say pins are even less secure because people usually set it up as something like their birthday and thieves also often simultaneously steal some id card in a wallet which has exactly that.

A screen pattern is a different way to enter a PIN with no duplicate digits. Both PINs and patterns rely upon the security processor to resist bruteforces.

It could be disabled from the bios somehow if you knew the bios password or the bios could be reflashed with a programming Clip directly on the bios flash chip itself.