You didn’t answer the biggest question: being able to read /etc/passwd does not imply being able to read any of the sensitive files listed under “What files could somebody steal? Well, there’s always:”. Did you actually test any of those?
I only tested passwd at the time and I don’t currently have access to the 6s to test the other files. I can report back whenever I get access to that phone again.