@lmarik81 - I think the pointed question you need to ask is:
"Suppose I want to intentionally blow my Knox warranty flag on my retail device - will the retail device become equivalent to a dev device at that time?"
I *think* the answer is "NO - you will still not be able to boot unsigned kernels."
But it would be better if someone with a blown Knox retail device can validate the above with a "yeah, I tried that on my (blown Knox) retail device and it didn't work" ... either that or refute that assertion from contrary experience.
Direct first-person experience is very desirable here.
[Edit]
@lmarik81 - mind saying how you blew yours? Flashing the recovery partition, or something else?
.