Originally Posted by v8s10
After booting to gameOS from petitboot (just after writing the nor, which only a very small section is actually changed) it is still booting the cex firmware that is installed. It isn't on debug fw yet, so there are no debug options. All this does is allow you to install a debug firmware.
You don't understand what I mean. To clarify what I'm getting at:
You change the target ID to DEX, it's now a debug PS3, yet it still happily boots CEX FW, right? Can you power-cycle the machine and still boot CEX FW? Because if so, it makes me wonder if the opposite is true, ie. convert target ID back to CEX after installing debug FW and be able to boot DEX FW on a retail machine... this is why I asked if this would only result in a hybrid where nothing really works.
 Or am I wandering into "sensitive" territory here? Perhaps a TB/Cobra dev could pop up and tell me I'm wasting my time/nothing to see here/etc
[edit2] As in, you mount the flash r/w very early in the boot process, read/decrypt the target id sections, convert/encrypt them on a microcontroller and flash them back, then boot a modified FW that appears to be retail but actually is a hybrid debug.
[edit3] That doesn't make sense after thinking about it for a bit. Never mind