I don't think you grasp what the TouchID sensor's role is, in the secure chain of trust. Regardless of TouchID being disabled IN SOFTWARE, and the user having implemented PIN protection instead of TouchID, the actual *physical* sensor that was paired to YOUR PHONE and associated chip/crypto/unique signature/hash/whatever is BONDED in some secure form, and trusted by the chain of trust ON YOUR DEVICE. If that is removed and replaced with a part WHICH IS NOT YET TRUSTED, the chain is broken.
Your comment is like saying "Oh, the front door has been kicked in and the locks busted off, and anyone could walk in, but I only use the BACK door..." you're STILL POTENTIALLY OPEN TO ATTACK!