So the FF camera can be fooled using pictures. This would be news worthy if the FF cam couldn't be cheated.
But that's not where security features fail. The question is how long it takes the thief to shut off the device.
If one (sophisticated) thief has physical possession off any phone, it's over. Once turned off to dodge tracking, in a controlled (no reception) environment, any phone's feature can be hacked.
	
	
		
		
			you mean all the photos you took that are stored on the SD card on the phone they stole/you lost wouldn't work??
		
		
	 
Phone doesn't have a SD card. Still, actual possession of a device>all security features. Face unlock is cute but all it can do is stall thief's access to your phone but my guess is first thing a thief would do is shut the phone off anyway, remove from scene and then ponder the hacking options. 
The actual theft is key here, even a fool-proof camera would be useless once the phone is lost and the thief is removed enough from the scene to hack it.