Just a shot in
the dark, but the cheapest copy protection is to flip some
 bits on the data bus. If you read a PROM on a programmer, all you see is
 garbage, until you figure out how the data bus was connected.
 
 That's possible, but the image is loaded via MOP or tftp...so that'd
 either require instructions to flip the bits or an executable to flip
 them, no?
 Or....off the flash card.
> Usually, nobody wasted the money to copy the ROM into an expensive SRAM
> to run it ... 
 
As I said, it was very dark ;-)
If you download it and run it from RAM, it could be encrypted ...