Surely people are over complicating this. It doesn't matter what state the password is in if Facebook can access their own databases. They just have to swap out the hash and give the new one to the police no? 2FA must be a database entry as well can't imagine it's that hard to turn off.
There's no need for cracking when you can actually edit the data.
(Ignoring the legal side)
Yep your right just swap out the hash for a known password, that's probably the backdoor this is referring too, i.e access to the database.
https://bgr.com/2018/05/04/facebook-profile-backdoor-account/