I don't see a problem with "2. Integrity Attacks (six devices)".
While of course proper XSRF protections must be applied to the firmware update script, I'd like to have a device where I can inspect and modify the firmware, thank you very much.
(Or, at the very least, expose u-boot over some interface that's available without destructive dismantling of the device)