Earlier quoted context omitted.
A security model that the user does not understand and contains traps is not a good security model.
OK, but what model would you suggest? Apple has no adequate way to actually verify who anybody is without (a) forcing them to physically visit one of a small number of offices (it can't be every store), and (b) probably charging a significant fee to cover the cost of doing real verification. And even that demands assuming that the identifying information on the account is right.
Even with their strong privacy fundamentals they know more about their account holders than any single business should.