The described attack in TFA seems to involve learning the phone owner's passcode (for the phone), so no lock screen shenanigans needed.