+1 on @arbitraryreadwrite post. I'm sure it's easier to hijack a 4-digit pin than a 14-character pass phrase, although no difference when a keylogger is installed on your device. And I really don't like the thought that a photo of me can be used to circumvent biometrics on "certain" Android devices with cheaper cameras. So my vote is against the use of PIN unlock (there must have been a reason 1P dropped it from 7 to 8).
As far as
* "And how many are on Android 11 or higher, meaning the latter could be implemented using Keystore's AUTH_DEVICE_CREDENTIAL, delivering some real security?"
I would expect future revs of 1P 8 to be better aware of Android version, since Android support on 8 for version < 9 was dropped, and take advantage of any inbuilt security / authentication mechanisms that didn't exist a year ago when 8 was initially rolled out. Sounds simple, I know, unless you happen to be a developer...