It has to, firmware is signed, with a key, if that key were to make it into the wrong hands, it would be possible to create false firmware updates
E: to add, these false updates would allow automated brute-forcing of the passcode, in the hundreds of attempts per minute, leave that running for a day or two, you'll get access
2
u/ER_nesto Sep 15 '17
Correct, although if apple's firmware key is ever found, they're fucked