" it would be rather slow, since you could only try about a half dozen PINs between NAND copies"

Arguably so, although the sensible approach would be not to keep re-flashing the NAND but to connect a piece of hardware emulating it that reverts instantly to the original image. Still need to keep rebooting the phone though, so a really professional attack device might also have the DRAM de-soldered and emulate that too - and just keep going...

