

The initial pin that most folks have to enter is needed to decrypt the partition with user data. This is not 100% foolproof for keeping LEOs out since there are many known, and likely more unknown, ways to brute force these but it is still the best option.
This stuff is literally a bullshit(1) machine. How can you fix it without making something else entirely?
(1)