Hah
That might work, but since boot1 is editable by Ninty (whereas boot0 is not, as its stored physically inside the CPU die), they could always do as Sony did, when the metldr on the ps3 was breached. Sony moved everything one step higher up in their bootchain (to the bootldr, which we did not have access to at that time).
Since boot1 is editable, Ninty could likewise move stuff up into the bootldr or change the bootloader in some way, so we are out in the cold again :/ Well, in terms of downgrading and emuNAND, atleast.
The charm of IOSU is mostly, that it gives us access to everything we could ever need for homebrew on the current FW (and later FWs until the vulnerability is patched).