It sounds much easier indeed.
As for security (for the overly paranoid),
if someone reflashes the CPU (assuming he can have full access for a long
time, like when stealing it), as long as your drive is encrypted, I don't see
any advantage in allowing re-flashing through hardware only.
I suppose a GRUB password can be a hurdle to prevent software re-flashing.
But again, what's the point in securing this part? It's not like it's likely
to happen, and even if it does, it's not like you wouldn't notice since you
wouldn't be able to boot.
I mean the attacker would need the exact naming you used while setting up
Libreboot.