That would work, but it's more elegant to dig into the bootloader. As long as you don't have the pw you'd have to repeat this approach. Suppose you manage to put your own system on the SD, the bootloader would still have the lock.
Edit, even simpler: hook up a logic analyser and the password should be among the first captures.