Biggest lesson is Apple should allow you to downgrade OS, especially on old devices.
Or release some sort of open version once device is EOL'd.
Even if they did, would you recommend them allowing the downgrade without the passcode? Any action that requires a passcode doesn't help this user.
Then an attacker could load an older, exploitable OS and gain access.
Even if they did, would you recommend them allowing the downgrade without the passcode? Any action that requires a passcode doesn't help this user.