NPR was playing this story up as if it's a blow for Apple - is it really? Isn't the vulnerability the fact that the phone has no secure enclave, and so the timeout/wipe can be worked around by external access to the flash? Isn't that the whole reason the newer phones were upgraded? Older device fails, newer device with improved security doesn't. That's not a blow to Apple, that's the way the world works.
As far as I've been able to figure out, the Secure Enclave does not have its own storage. The proposed attack of cloning the phone's flash memory would work just as well on a new iPhone 6s. A lot of people are assuming that the Secure Enclave would prevent this attack, but I've not yet been able to find any basis for that assumption. The main security advantage of newer phones in this context is that Touch ID makes i…
Their own whitepaper defines it:
A dedicated area of NAND storage, used to store cryptographic keys, that can be addressed directly and wiped securely. While >>it doesn’t provide protection if an attacker has physical possession of a device
(emphasis mine)
However, it appears that the FBI attack only worked because the people in question used the 4 digit pin. A strong passcode is the way to go and protects you from these kinds of brute force attacks.