I popped the back plate off of my new Aura off yesterday. It looks like hacking will be pretty easy, though I'm not sure I want to have to pop the back off very often.
I had read that some newer models had the NAND flash soldered onto the board, but mine is a Sandisk sdcard in a slot. So I pulled the card out, dd copied it, and I can restore if I do anything really bad that makes it stop booting.
There is a well-marked ttl level serial port on the back. uboot is accessible and allows for interrupting boot. You can log into a root shell onto the running system without a password. It's basically open for business.
I will spend some time playing with the console, and then investigate the patch set published by geoffr here:
https://www.mobileread.com/forums/sho...d.php?t=260100