Hacker News new | past | comments | ask | show | jobs | submit login

Hey! I'm Rithwik, one of the authors of the article, happy to answer questions etc!



Mainly just wanted to say, this is an absolutely fantastic hack and I loved reading about it - thank you for sharing!

I guess if I have one question, it would be... what else are you planning to do with your new Faraday cage?


I'm thinking of making it easy to "teleport" to any location within the cage

Imagine typing in coordinates or picking a location on a map, and then suddenly your phone or any other device is at that location inside the cage, by a combination of GPS, cellular and WiFi spoofing

My former manager called it a portal haha: https://x.com/masadfrost/status/1856467695606345756


Thank you for reading and the kind words! We're almost looking forward to this loophole being shut down to really make things a tad bit more challenging haha

We've got some ideas for the Faraday cage—a whole bunch of networks research and hacking that we can do without messing up live systems! It's also really nice to be able to test a device in isolation, without worrying about whether it's phoning back home in some way.


> We're almost looking forward to this loophole being shut down to really make things a tad bit more challenging haha

This is a great attitude in the face of a pretty sad 2024 reality: that the manufacturer of a device is expected to intentionally go out of its way to remotely stop users from using the device they bought in the way they want to use it.


I'm a bit perplexed about region handling, maybe you could shed some light on it. I have an iPhone from Canada, with a Canadian Apple account (Canadian CC/billing address, set location to Canada in App Store), but live in Spain for the last few years. I am still fully "Canadian" according to Apple. I don't get any of the 3rd party App Store stuff that's region locked to the EU, and have access to Apple Intelligence and other features not available in the EU.

I can't give the hearing aid feature a test because it's not available in either Canada or Spain, but I am wondering what the difference is (if any) between the hearing aid region lock and other geo-locked/geo-enabled features Apple has.


You can login with a second account that is an EU account, my wife went this route. You get the best of both worlds.

I ended up transferring my account to an EU account (pro-tip, you may be on the phone with Apple support for 6+ hours if the automation fails). I still have access to both US-specific features (like Apple Cash in USD and the feature in this article) and EU-specific features (like the new app store stuff).


Are you _physically_ in the EU too?

I'm surprised that this worked for you, my main Apple ID is a German one, with active CC/subscriptions/etc; but I am physically in Japan and definitely don't get to play Fortnite on my phone.


Yes, I'm physically in the EU. I'd be curious if you set your computer up as an access point and connected to a VPN (so the phone won't know if it is on a VPN) and then use an exit point in the EU. You could even go so far as spoofing GPS in your house using SDN to even make it think it is in the EU. (just don't forget to make the testing room a faraday cage to prevent any airplanes from getting confused).

I'd even be happy to repeat your cellular signals here in the EU, so you connect to EU towers.

That would be entertaining to see if it worked.


Awesome article. This kind of hacking casually showing iOS app behavior is another world, especially because I thought they were so locked down. How did you get started, any recommendations?

Since you did not end up having bought yourself a very expensive set of earphones, what earphones do you use — or want to get?


haha, I think I've got many miles to go before I'm qualified to answer this :')

I've just been hacking away at things since I was in middle school, am lucky that there's some transfer. LLMs have also been a huge unlock—really cool to be able to try things at near speed of thought!

> what earphones do you use — or want to get? I'm very happy with my Shure Aonic 3s, a very loyal IEMs guy!


In the true spirit of 2600!


That's a really awesome hack, thanks for sharing. I was slightly surprised that you had to go as far as spoofing a wifi network actually but it's great you figured it out.


Loved the article, thank you for sharing. How happy are the grandparents with the hearing aid functionality? Is it working well for them and how is the battery life?


It's all too early to tell, but we'll know after a week or so. The battery life thing is not seeming like a big problem, since the existing device needs batteries changed every few days or charged every night.

As for the sound quality, a few of our grandparents have tried it, and while they say it sounds 'different', it's not necessarily bad. Grandma was actually quite content even with just the old EQ settings that shipped pre iOS 18 for folks with hearing issues.

Thanks for the kind words!


The hearing test on one of the images shows a ‘profound loss’. Does the hearing aid feature work for such a significant loss, or does it disable for any result beyond moderate loss?


The feature only works when hearing loss is mild (26–40 dBHL) or moderate (41–60 dBHL). We had to repeat the test a few times to get it in the range and enable it.

https://support.apple.com/en-in/120991


Thanks. Any tips on how to do this while keeping the hearing profile as close to reality as possible?


Hi Rithwik -- great work. My Nana would have been thrilled to know this was possible :)

If I can ask -- what program did you use to generate the code maps in your article?


Binary Ninja: https://binary.ninja/ :)

Think someone has already linked it below!


It's Binary Ninja: https://binary.ninja


They look a lot like the graphs that Hopper produces :)


Thank you for your work. In the substack write-up, you said: "There was more work to be done: we needed a reliable reproduction, and a concrete process." Could you elaborate on the process for unlocking?


Maybe I missed it but did you make or buy the Faraday cage?


We built it ourselves actually!

The first prototype was just aluminium foil, tape and hope, but we wanted something more solid so we built one out of n°100 copper mesh and some 2020 aluminium extrusions!


You can use a microwave oven as a very cheap faraday cage. Just don't turn it on.


The door of a microwave typically doesn't form an RF-tight seal. Instead there's a groove that forms a resonant trap at the microwave's operating frequency. So it'll probably block 2.4-GHz ISM-band stuff like Bluetooth (I don't actually know how wide the trap band is compared to a BT or wifi channel), but outside that band all bets are off.


I assume he needed it to have a small opening in the cage to shove the Raspberry Pi through it (to broadcast new SSIDs)


You are replying to the article author. He knows you can use a microwave oven as a very cheap faraday cage. He tried that, but it wasn't good enough.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: