1. My friend, 3dbrew says:
If bootrom was dumped, they would know exactly when ARM9 memory get initialized -> this means bootrom is not dumped?
We can't know when its initialized, because we can't know how much time the instructions take to execute.
In the Decaf Fundraiser page, it's clearly stated that the bootrom was dumped.
2. I not talking about disable NAND, I talking 2 physical NAND which can be switched by HW mod. Maybe there are other ways to do it, but this is my simple idea
Can you swap hard disks while the OS is running?
EDIT : excuse me, this was not this flaw that allowed bootrom dumping for core scene members.