Yeah. If you can futz with the hardware, pretty much any security can be circumvented.
Desoldering a SOC and replacing it with something similar enough but different in its trusted boot config is somewhat less trivial than "manipulate the firmware" though, at least in my opinion...