Even if those updates require signature verification with a public key stored in ROM? I guess the signing key cold get out or you could patch the firmware to skip the signature check (the way the initial iPhone was jailbroken)
We also literally just had the Windows key leaks within the last week. Un-updatable signing keys are still an uncloseable exploit vector. (And updatable signing keys are an uncloseable exploit vector. You can't win.)
Physical-access-only updates: yes please. We know what the security boundary is on those, and how to reset it.