I forgot something else, another trick we used to use on other motorola models (up until around the V9 where the game changed a bit) was to make use of "test point" locations on the physical pcb, which when shorted would result in the phone dropping into a "blank" mode when powered on, allowing bypass of all security entirely. Used to use this method to unlock the V3re and several other models back in the day. Problem with that is that this method generally applied to GSM phones, I never saw TP methods for CDMA devices. However, given that there was never much need to get around the encryption on older cdma devices, it was probably never fully explored or went poorly documented. Knowing moto, there is probably a similar method. Finding it though would be an entirely different story. First, we'd have to reverse engineer a schematic, etc, etc, etc... not to mention find someone with a MB810 or A955 board they are willing to donate to science.