The issue with that is, aside from the NAND flashes, we can not dump any other chips. The nands are "keyed" per box, and all the other chips are custom logic, with pinouts unknown to us. Not to mention its very possible the chips are burnt with the key at the factory, so its not writable at all.
If it's just a software issue, what's the possibility of a modchip that has the capability of being able to boot the retail console with software and run the console as a debug console? I know that not everyone would be thrilled with having to solder their $600 units. This seems like possibly and easier root than trying to exploit software on a retail unit... yes, no?