When I asked about this 5 years ago, I was told that for many processors you can still just JTAG them and get everything:
https://security.stackexchange.com/questions/189950/how-does...
Has this changed?