Can you bypass the user interface by connecting/mounting the disk (somehow) then have access to the file system and private keys stored there?
The nano s isn't simply an USB stick. The private keys are not lying around on a flash memory.
They are stored inside a secure element.
So, no. That's not possible. You need to enter the correct pin (within 3 tries) to access the private keys.
You can read more about the ST31 secure element and the architecture of the nano s here:
https://ledger.readthedocs.io/en/0/bolos/hardware_architecture.html