Personal opinion: flash chips of all kinds should be write-protected so that even a clip flash does not work... but they should have an authentication mechanism with, say, a 64 bytes passphrase that the end-user gets on a keycard. That way you'd need a literal "evil maid" in the household of the owner to do any modifications that might compromise the device.