More iPod Nano 7G discoveries!
gsch discovered that if you boot diags from WTF (instead of from bootloader), you actually get a serial console... with full memory read/write.
Turns out this works because WTF ships with an EFI UART/Serial driver, but the bootloader doesn't. So if you run diags from WTF, you get that very nice serial console. And since both WTF and the bootloader are signed, you can just send them over DFU.
Who need exploits when you have built-in functionality? :)