Partially incorrect; you can use someone elses nand backup, with an Infectus2, to flash the blocks 1 to 7. Those are the blocks that contain Bootmii, and are not encrypted by the ECC key. Everything after that, including system menu, IOSes, are encrypted with that key.
If you try to use...