Every single version of the iOS kernel has been dumped. That gives you most [0] of what you need to craft a modified version. The largest barrier to running these modified versions is getting the target hardware to accept them as authentic. All public bootrom/iBoot exploits on the iPhone 3GS/4 patch the bootloaders' RSA authentication out in some form or another. There are no public bootrom exploits out for iPhone 4S+ devices.
Thus, having the signing key (or the power to compel signing at will) is an incredible ability privy only to Apple.
[0] Some Mach-O information is lost. Decryption of the imgX formatted kernel is preferable.
Thus, having the signing key (or the power to compel signing at will) is an incredible ability privy only to Apple.
[0] Some Mach-O information is lost. Decryption of the imgX formatted kernel is preferable.