I've been poking at this already, and I'd venture a guess that the T2 will be breakable. The reason I think the XS and later are hard is pointer authentication codes, but that's more conjecture as I don't have a SecureROM dump from an XS. Plan to examine other parts of the boot-loader like iLLB, assuming they are not encrypted, for the ARM branch with authentication instructions...
I've been poking at this already, and I'd venture a guess that the T2 will be breakable. The reason I think the XS and later are hard is pointer authentication codes, but that's more conjecture as I don't have a SecureROM dump from an XS. Plan to examine other parts of the boot-loader like iLLB, assuming they are not encrypted, for the ARM branch with authentication instructions...