The articles says that the security sector is RSA-signed using a private key only Microsoft possesses, what if you also change the public key used for verification that is stored in the console?
It did get broken eventually (after years of trying!) by figuring out that the CPU stops being reliable at very low clocks, but it was not even remotely easy.