[...]
I wonder how long before someone figures out a way to update the firmware so that it creates an
unencrypted backup of your seed on the microSD card

I have tried the backup option. It creates a 12 word mnemonic that acts as the pass phrase to decrypt it.
Huh ?
What kind of backup is being generated if you still need your 12 word mnemonic ?
Are you sure that you need your mnemonic seed to
decrypt the
backup file ??
IMO, this wouldn't make much sense. The mnemonic seed should be the backup itself.
As i have understood it, it generates a backup (= encrypted mnemonic seed) which needs a password(?) to be decrypted.
When you create a wallet, it will give you 24 bip39 words to write down. After creating the wallet, if you choose the backup option, it will give you a 12 word 'passphrase' (if you want to call it that) to encrypt the file.
The 'backup' is essentially a system image, which includes the seed, as well as system preferences.
You can read about how it works here:
https://coldcardwallet.com/docs/backups'Background
The Coldcard is unique in that we offer a backup feature to save your wallet seeds to MicroSD card. Settings and other meta is saved as well. The encrypted file can be treated as any other file because we use AES-256 encryption, with a strong pass phrase.
Even using this feature, you should still have a paper-only copy of your 24 seed words. Use the encrypted backup feature for convenience and duplication.'