Earlier quoted context omitted.
If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.
The security of an ID is protected by the state. Screwing around with that is a federal, put your ass in prison, kind of breach, irregardless of your intention or the context.
ID is not a panacea, especially in this case. Apple is probably best to roll out some form of multi-factor auth.