If I were a breaking bad meth dealer and had all my buyers as contacts on that phone and all my incriminating chats, I wouldn't use biometrics to unlock it. But I'm not a meth dealer (and I'm not just saying that because that's what a meth dealer would say).
There is a spectrum of convenience vs. security. It depends on where you sit. I'm okay with the fingerprint, wouldn't go for the face.
Doesn't Android have the panic/cop switch where you force password over biometrics unlocking? It's not a 100% failsafe but it is a start.
I don't have much to say about the points you're making here. I have a feeling after we sit down and discuss this over coffee/a beer we will find out that we're pretty much on the same page.
The only thing I want to point out though it that the term "enshitification" was coined for online platforms. It describes a business catering full hog to the needs of the users to create a following, then sell access to that following to other businesses, until both followers and b2b customers are locked in and get milked for every cent possible. From the user POV that's when the service enshitifies ~~DVD~~ and the b2b customers are between a rock and a hard place. Your cable example follows a similar mechanic but since it is not online it is technically not enshitification as dumped into the world as a term by Corey Doctorow.
That's just minor pedantry that you're naturally free to ignore as well. As I said before, I don't see us disagreeing on the overall point you're making. Very eloquently, I might add.
Edited typo