Originally Posted by cme
but I guess the magic happens within the original "PRS-T1 Updater.package" from the root package, because after it's done restarting, everything is as it was before.
Yes it does happen there.
The "PRS-T1 Updater.package" from the root package looks like (i.e. actually is
) a regular firmware update package to the reader, but doesn't contain any updates, but only the update script that is part of all these firmware update packages. And this (root package) script does then it's magic, because as a trusted updater script it has full access to the device.
Unfortunately, these updater packages are encrypted with a key specific to the reader model, so unless we don't know the key for the T2 (for which it would be necessary to have root access to the device), there won't be a root package.