I'm guessing the programmers at Apple aren't stupid, there must be way around this
If the person can't get through your password though, how will the mac connect to the internet for it to update find my iphone anyway? As you suggested it would update without the theif getting through your user password.
iCloud and Find my Mac are always running, but when iCloud locks the Mac, it locks itself too.