[00:00.000 --> 00:00.600] ...out of the hallway. [00:01.240 --> 00:05.160] And again, that's for the unscheduled tracks, if you want to say something on your own. [00:05.480 --> 00:07.820] And we have all kinds of activities downstairs, like we were talking about. [00:08.160 --> 00:11.320] Please don't turn off the hotel TVs in the lobby. [00:11.480 --> 00:12.820] I know, it's tempting. [00:13.400 --> 00:15.660] I think we put black tape over it anyway to help them out. [00:16.440 --> 00:20.340] But the hotel's been great to us, and we're glad that it's still standing. [00:20.700 --> 00:27.460] I think to ensure that it keeps standing, let's treat it with respect, the respect it deserves, and who knows what the future will hold. [00:28.460 --> 00:30.840] So, shall we give the official intro? [00:36.880 --> 00:38.120] Caught me a little bit unprepared there. [00:38.380 --> 00:39.180] Are you guys ready to go? [00:39.580 --> 00:39.840] Yeah. [00:40.060 --> 00:42.420] Okay, Phillip Torrone, Lady Ada, give them a round of applause. [00:47.840 --> 00:51.860] Alright, well, we have a special announcement about cell phones. [00:52.020 --> 00:54.280] So, we have cell phone jammers up here, so... [00:54.280 --> 00:57.520] First, you don't have to worry about turning off your cell phone. [00:57.520 --> 00:59.660] Yeah, it actually doesn't matter, so... [00:59.660 --> 01:01.420] Sorry, you can't Twitter or use your cell phone right now. [01:04.820 --> 01:08.660] Alright, so I'm Phil Torrone, and this is Limor Fried. [01:08.780 --> 01:09.000] Hello. [01:10.500 --> 01:16.280] A little bit about us before we get started, so you know what you're in store for. [01:16.280 --> 01:18.420] I'm Senior Editor of Make Magazine. [01:18.640 --> 01:19.100] You guys hear Make? [01:19.400 --> 01:20.280] Yay, Make! [01:24.340 --> 01:26.200] Because people always ask. [01:26.360 --> 01:32.060] We're now around almost four years, we have 125,000 in circulation, around 45,000 subscribers. [01:32.620 --> 01:40.840] The website has a lot of people who visit it, which is great, because there's a huge community of people building things and sending their projects to us now. [01:41.860 --> 01:46.140] Our Maker Faire that we do every year is up to 65,000 people. [01:46.460 --> 01:48.520] So, it's a giant event in San Francisco. [01:48.540 --> 01:50.160] We also do one in Austin. [01:50.380 --> 01:53.000] And here's some of the things that we've been up to at Make. [01:53.660 --> 01:55.460] You can see some of the covers. [01:56.440 --> 01:59.640] We're quarterly, so it comes out every few months. [01:59.640 --> 02:04.980] Then we branched into Craft for people who like to do more of the softer side, literally, of hacking. [02:07.880 --> 02:12.760] And then we decided that, well, what other weird thing can we do? [02:12.820 --> 02:17.240] So, we have a Japanese version, which is kind of ticking off, which is great. [02:17.400 --> 02:21.380] And I actually like... I can't really read Japanese, but it looks cooler in Japanese. [02:24.620 --> 02:27.020] And this is Limor, her business, Adafruit. [02:27.260 --> 02:27.400] Yep. [02:27.980 --> 02:28.380] So... [02:28.380 --> 02:30.060] You could probably just look at the screen. [02:30.200 --> 02:31.040] I can see the screen just forward. [02:31.580 --> 02:31.980] Oh, okay. [02:31.980 --> 02:35.920] So, two years ago, I sort of talked about the Wave Bubble project. [02:36.080 --> 02:38.720] This is an open source RF jammer, which is... [02:38.720 --> 02:40.560] Actually, if you look, it kind of looks like this. [02:40.720 --> 02:41.540] This is the beta. [02:41.960 --> 02:54.960] And basically, you know, I've just been releasing open source hardware, electronic kits, basically more soldering, microcontroller programming, firmware, analog, digital, that kind of stuff, because I think that's kind of interesting. [02:54.960 --> 03:00.760] And I found that a lot of people are also interested in building these sorts of technologies, especially technologies that are illegal. [03:01.020 --> 03:05.660] For example, it's illegal to own, use, operate, sell a cell phone jammer. [03:06.180 --> 03:10.460] So, I mean, you can buy them, but there's a chance that those stores will be shut down. [03:10.620 --> 03:17.840] But what's cool is that if you know a little bit of hardware, a little bit of soldering, you can create your own cell phone jammer using parts from Mauser and DigiKey. [03:17.840 --> 03:20.500] So, for like $100 of parts, you can build your own. [03:20.800 --> 03:25.180] And there's no way to stop people from buying these components, because they're just everyday electronics. [03:25.300 --> 03:25.920] And that's what I like. [03:26.060 --> 03:29.640] It's creating something interesting from stuff you find around you. [03:31.400 --> 03:31.780] So... [03:31.780 --> 03:33.540] Oh, this was in a cab. [03:34.440 --> 03:38.040] You know when they're driving, and they're talking, and they're swerving all over? [03:40.420 --> 03:40.700] Yeah. [03:41.860 --> 03:42.140] So... [03:43.200 --> 03:43.920] And you know what? [03:43.920 --> 03:45.100] It's not even being passive aggressive. [03:45.240 --> 03:46.040] I'm like, hey, watch out. [03:46.080 --> 03:46.980] You almost hit that person. [03:47.120 --> 03:48.820] Hey, you know, you should probably get off the phone. [03:48.960 --> 03:50.020] Like, you're not supposed to be on the phone. [03:50.260 --> 03:51.300] And he's like, oh, whatever. [03:51.620 --> 03:52.340] And then... [03:53.060 --> 03:54.180] And there was a lot of, hello? [03:54.280 --> 03:54.720] Can you hear me now? [03:54.780 --> 03:55.180] Can you hear me now? [03:55.760 --> 03:56.040] Anyways. [03:56.540 --> 03:57.460] So that's an action shot. [03:57.580 --> 04:00.300] You guys will enjoy if you're visiting the cab situation. [04:01.100 --> 04:02.220] Maybe build a cell phone jammer. [04:03.060 --> 04:06.860] This is another project that I did a couple years ago, which is a... [04:08.040 --> 04:09.100] Bleepy Bloopy Box. [04:09.360 --> 04:11.980] It's an open source TV 303 clone. [04:12.200 --> 04:15.460] So that's a synthesizer from 20 years ago more. [04:15.600 --> 04:16.440] Actually, from 1984. [04:17.280 --> 04:20.320] That was discontinued by Roland, Japan. [04:20.680 --> 04:23.420] But a lot of people still want these synthesizer boxes. [04:23.660 --> 04:28.940] So a friend of mine and I, when I was in college, decided, hey, let's reverse engineer it. [04:29.140 --> 04:36.660] And because there's no patents valid anymore, because it's been more than 20 years, let's make a clone that, again, you can build using off-the-shelf parts. [04:36.660 --> 04:40.280] And you can make this synthesizer no longer available. [04:40.500 --> 04:41.620] It goes for $2,000 on eBay. [04:41.740 --> 04:43.140] You can build your own for $200. [04:45.600 --> 04:47.820] And here's some, you know, blinky light kits. [04:47.920 --> 04:51.040] I just wanted to show a couple projects so you can see where we're coming from. [04:51.500 --> 04:58.000] This is a LED bicycle wheel animation kit, so you can make it Pac-Man when you bike. [05:01.660 --> 05:04.780] And I also did some sort of small educational kits. [05:04.920 --> 05:05.680] This is the mini-pop kit. [05:05.800 --> 05:09.960] This is just picking your own Persistent Division toys for like under $17. [05:10.620 --> 05:14.080] And I like the idea of low-cost introductory electronics. [05:14.420 --> 05:16.100] Yeah, this one when you wave it, it spells out words. [05:16.100 --> 05:25.180] So what's cool is that Mitch Altman, who's giving the talk after this, and you should definitely stay for, he said, well, you know, I want to build this brain machine, which is this thing that makes you trip. [05:25.340 --> 05:25.640] I don't know. [05:26.140 --> 05:26.860] It didn't work for me. [05:28.180 --> 05:30.100] But like, he's a real child of the 70s. [05:30.140 --> 05:32.780] So he can explain it to you, and I'm sure he will in an hour. [05:33.360 --> 05:35.720] And he took this mini-pop kit and he modified it. [05:35.860 --> 05:41.760] And he even gives workshops now, and I think he's giving a workshop either today or tomorrow on how to build these using the mini-pop kits. [05:41.760 --> 05:42.320] So that's cool. [05:43.100 --> 05:46.720] And this is an Altoids 10 MP3 charger. [05:46.720 --> 05:49.100] So it's another small educational kit. [05:49.880 --> 05:52.640] And this is another thing I worked with Mitch Altman on. [05:52.760 --> 05:56.220] He invented the TV-B-Gone, which is that little remote control you can turn off TVs. [05:56.480 --> 06:03.960] But the problem with the TV-B-Gone is, although it's awesome and it turns off many TVs, it only works up to like 30 feet, which is totally not enough. [06:04.080 --> 06:08.020] So we worked together to build a version that can go up to 200 feet. [06:09.460 --> 06:12.680] Yeah, this one made its debut at CES. [06:12.900 --> 06:14.240] I don't know if you saw. [06:15.060 --> 06:16.700] So it can turn off a lot of TVs. [06:16.820 --> 06:17.360] It's good. [06:17.540 --> 06:20.200] It has like four LEDs and it's like wide and narrow. [06:20.420 --> 06:26.120] And what's cool is that there's a community on the forum of people who are modifying this kit and they're like, four is not enough. [06:26.140 --> 06:27.100] I need 18 LEDs. [06:27.380 --> 06:29.000] It needs a six-volt battery pack. [06:29.240 --> 06:31.220] I need it to be attached to my cap. [06:31.240 --> 06:32.860] And so everywhere I look, TVs turn off. [06:33.440 --> 06:37.780] There's this hacking and modification of these existing technologies. [06:37.780 --> 06:45.840] And because it's all open source, there's no like, oh, I have to understand what the chip is and extract the firmware and use acid to take the die out. [06:45.920 --> 06:46.180] No, no, no. [06:46.240 --> 06:47.040] It's all open source. [06:47.320 --> 06:48.280] It's easy to hack. [06:48.440 --> 06:49.900] It's, you know, Kickstarted. [06:49.940 --> 06:53.440] So you just go in and say, oh, you know, how do I connect extra LEDs? [06:53.660 --> 06:54.660] Oh, I just add them on. [06:54.760 --> 06:55.100] That's it. [06:55.200 --> 06:55.640] Okay, cool. [06:55.760 --> 06:57.040] This is a hack that I can do. [06:57.320 --> 07:01.600] And if you're younger, this will get you started so that you can continue on to more advanced hacking. [07:02.640 --> 07:05.980] And then I, you know, lately I've been working on Arduino-based projects. [07:06.200 --> 07:08.120] That's an open source microcontroller platform. [07:08.340 --> 07:10.920] So this is a DIY GPS logger and tracker. [07:11.800 --> 07:17.120] So, you know, maybe next HOPE or the next conference we go to, we'll talk about some of the projects we're doing with that. [07:17.340 --> 07:19.340] How many people here know about Arduino? [07:20.380 --> 07:21.280] Yeah, wow. [07:21.500 --> 07:21.640] That's a lot. [07:21.960 --> 07:24.340] So that number, every time we're out, it's... [07:24.340 --> 07:25.080] It was like six people. [07:25.340 --> 07:26.620] Yeah, before it was like one guy was like, Arduino. [07:26.620 --> 07:27.300] Yay. [07:30.380 --> 07:35.260] So what we're going to be talking about today, and this is a new kit, is a SIM card reader kit. [07:35.540 --> 07:39.700] So I don't actually own a cell phone because I own a cell phone jammer and they're not very compatible. [07:40.120 --> 07:46.820] But I think it's interesting that, you know, a couple of years ago, maybe 10 years ago, everyone was like really into reading mag stripes. [07:47.160 --> 07:52.380] But nowadays we don't really, I mean, now there's actually like RFID style cards. [07:52.740 --> 07:55.580] But it's interesting that I never actually learned about SIM cards. [07:55.580 --> 08:04.660] And even though they're in almost every phone, and the technology behind SIM cards is really interesting, but all the information I tried to find online was really kind of archaic. [08:04.800 --> 08:06.240] It actually was difficult for me to understand. [08:06.540 --> 08:18.600] So I wanted to build something that, even though this is sort of an older technology, makes it really easy and straightforward to understand how SIM cards work and why they're secure and how you can crack that security. [08:19.920 --> 08:28.520] And one other thing that, this is a project that we worked on together, was we decided to start a laser etching business, an open source laser etching business in New York City. [08:28.640 --> 08:32.480] So we got this laser, it was $20,000, and we paid it off in about six months. [08:32.600 --> 08:34.980] And what we were doing is laser etching laptops. [08:35.320 --> 08:37.940] So if you've seen laptops around, we etched these. [08:38.100 --> 08:42.120] So we take perfectly good Macs and void the warranties and people pay us. [08:43.800 --> 08:44.540] Go figure. [08:44.820 --> 08:45.760] Steve Jobs' nightmare. [08:45.880 --> 08:47.740] We also tried to do other things, like this is food. [08:47.860 --> 08:49.820] We put sushi instructions on Nori. [08:51.320 --> 08:51.740] So... [08:51.740 --> 08:56.000] We actually, we put the faces of people we don't like on tortillas, and then we eat them. [08:56.280 --> 08:56.620] Yeah. [08:57.500 --> 09:00.820] It's like a weird, like, laser etching millennial voodoo. [09:00.940 --> 09:06.420] So we put all this information out, and there's around 20 laser shops that opened since we did this. [09:06.500 --> 09:07.500] We put all the files, everything. [09:08.180 --> 09:13.400] Mostly because we were tired of people emailing us saying, oh, I can't come to New York City, can I send you something? [09:13.500 --> 09:15.100] We don't want people to send us their laptops. [09:15.460 --> 09:20.160] So now people in all parts of the world are starting their own laser etching businesses. [09:21.120 --> 09:22.160] Okay, so that was the intro. [09:22.500 --> 09:24.440] But the rest is going to be a lot faster. [09:24.820 --> 09:31.160] So, two years ago we came here and we did a talk called Citizen Engineering, where we actually did a full talk about that sort of stuff. [09:31.240 --> 09:36.140] This reemergence of hardware technology, sort of the new era of hacking and freaking and... [09:36.720 --> 09:39.080] Yeah, you can download the video or buy it if you think they have it here. [09:39.120 --> 09:39.880] Yeah, it's online for free. [09:39.880 --> 09:41.140] I've seen a bunch of people have it. [09:41.620 --> 09:43.440] But what we thought about... [09:43.440 --> 09:46.500] So, we've been going to this conference for like 10 years. [09:46.720 --> 09:47.000] I've been... [09:47.000 --> 09:48.820] I didn't go to the first HOPE, but I went to Beyond HOPE. [09:48.820 --> 09:50.200] And I think that was about 10 years ago. [09:50.820 --> 09:53.840] And another thing we noticed when we looked at some of the speakers here, is there's... [09:53.840 --> 09:54.660] I think there's... [09:54.660 --> 09:58.160] A lot of people are talking about this as the last hope. [09:59.420 --> 10:10.080] And there's this understanding or at least this sort of feeling that the hacking scene as we knew it in the 90s, and if you're 17, maybe you don't remember this, but it's kind of dead. [10:10.700 --> 10:13.220] Not in like a bad way, like, oh my God, it died. [10:13.360 --> 10:13.880] How tragic. [10:14.080 --> 10:16.900] It was on its deathbed and we gave it oxygen, but it couldn't make it. [10:16.900 --> 10:25.920] But there's definitely been a transition from this early hopes, you know, 1994 to 2000 to 2002 to 2008. [10:26.300 --> 10:26.720] Yeah. [10:27.960 --> 10:30.660] And there's also a lot of nostalgia, you know. [10:30.820 --> 10:43.500] These conferences are filled with things from blue boxes, red boxes, exploits, buffers, IRC, text files, drunk jerks, getting kicked out of cons, drama. [10:43.500 --> 10:48.280] What were some of your... Shout out some of the things that happened in like the 90s and the hacking that you liked or didn't like. [10:48.420 --> 10:49.260] Just shout out some stuff. [10:49.640 --> 10:50.220] Jail time. [10:50.360 --> 10:51.440] Jail time, yeah. [10:52.280 --> 10:53.700] Yeah, that's a good one. [10:53.880 --> 10:55.220] Yeah, that's very passe. [10:55.500 --> 10:56.680] Yeah, and actually... [10:57.260 --> 11:03.980] And we'll show you pretty soon what have been the worst thing we could have possibly done probably in the late 90s, but now it's like, oh, cool, like, now it's fun. [11:04.140 --> 11:05.480] So it's interesting, times do change. [11:07.740 --> 11:09.560] So now there's other things. [11:09.740 --> 11:15.420] So instead of doing things that we all used to do, now there's white papers, everyone's security consultants. [11:15.640 --> 11:16.940] They're doing pen-testing. [11:17.120 --> 11:17.820] They have book deals. [11:18.020 --> 11:18.820] There's VoIP. [11:19.100 --> 11:21.440] There's boondoggles. [11:21.820 --> 11:22.280] Yeah. [11:22.560 --> 11:24.240] People that war dial, they war drive. [11:24.740 --> 11:27.480] It's kind of this new old. [11:29.020 --> 11:35.600] And so what we noticed was that as some things ended, some things began, hardware started to happen. [11:35.760 --> 11:40.020] Like, you know, based on a number of people here who knew about Arduino, you know, that's a lot even in two years. [11:40.540 --> 11:42.440] And people are buying more kits. [11:42.740 --> 11:47.740] Make is one of the things that we've been working on for a while, and we can't seem to keep up with the demand. [11:47.880 --> 11:50.840] There's more and more people wanting to do hardware than ever before. [11:52.140 --> 11:52.620] Yeah. [11:52.760 --> 11:55.980] So citizen engineer is something that we put together. [11:56.320 --> 12:00.780] We wanted to look forward, not back, but we also wanted to build on the past. [12:01.080 --> 12:05.960] So we like the idea of the technologies that got us all here. [12:06.740 --> 12:09.100] And we think they're still interesting. [12:09.500 --> 12:14.000] But what we wanted to do is pull it all together and show it maybe in a modern way. [12:14.680 --> 12:17.960] So we made a video, and it's kind of like a short film. [12:18.260 --> 12:24.180] We just debuted it just like a few minutes ago on the web, and we're going to show you some snippets. [12:25.060 --> 12:27.600] It's going to always be non-commercial, non-sponsor. [12:27.600 --> 12:29.500] We're going to try to do these as often as we can. [12:30.480 --> 12:32.920] It's only for people like all of us here. [12:33.040 --> 12:34.660] We don't think anyone else is going to like it. [12:34.660 --> 12:36.400] And we kind of hope they don't either. [12:37.680 --> 12:38.400] But we'll see. [12:38.920 --> 12:39.300] So... [12:40.420 --> 12:41.340] I'm going to start... [12:41.340 --> 12:42.600] Do you want to talk about the introduction? [12:42.940 --> 12:43.160] Yeah. [12:43.660 --> 12:49.160] One of the things that we wanted to do, too, is a lot of the things that Limor's worked on, she made the x0xb0x. [12:49.360 --> 12:53.380] So people take the x0xb0x and then make interesting music. [12:53.520 --> 12:55.280] So we wanted to use that as our soundtrack. [12:55.480 --> 12:56.800] So now we've got a bunch of cool music. [12:57.020 --> 13:03.920] There's also artists who are using processing, which is part of the Arduino development environment, similar ID. [13:04.500 --> 13:05.780] They do interesting art. [13:05.980 --> 13:09.640] So we talked to an artist who does really interesting art with processing. [13:09.920 --> 13:13.560] So this is the introduction and then we're going to show you some other snippets. [13:14.200 --> 13:14.500] So... [13:14.980 --> 13:20.040] Yeah, if we can get the house lights off from now forward, that would be great. [13:21.480 --> 13:23.100] I don't know if anyone has access to that. [13:23.140 --> 13:23.620] Oh, look at that. [13:23.800 --> 13:24.380] Wow, that's fast. [13:25.560 --> 13:26.200] No, I close it. [13:26.920 --> 13:27.320] OK. [13:27.840 --> 13:28.500] So I'll start here. [13:28.520 --> 13:29.000] Is it room blurry? [13:36.770 --> 13:37.050] Oh. [13:38.650 --> 13:39.610] Or is it she be louder? [13:39.830 --> 13:40.770] Yeah, maybe.... louder? [13:41.090 --> 13:41.350] Louder? [13:42.830 --> 13:43.230] OK. [13:43.550 --> 13:43.910] I get it. [14:15.350 --> 14:16.710] Okay, so that's our introduction. [14:16.910 --> 14:21.730] Now what we are going to do is skip ahead to the first part. [14:21.870 --> 14:25.770] So what we did is we talked about GSM phones, SIM cards, all that stuff. [14:25.870 --> 14:27.250] You can download the video later. [14:28.010 --> 14:34.030] And then what we do is kind of demystify some of what goes on behind the scenes with electronics. [14:34.590 --> 14:41.030] So we do a parts tour of all the things that you'll need. [14:42.530 --> 14:47.810] So basically this first project is, you know, every GSM phone has a SIM card in it. [14:47.910 --> 14:50.750] And there's actually a lot of really interesting things going on in SIM cards. [14:50.870 --> 14:59.070] A lot of the stuff is actually explored back in 98, especially when Ian Goldberg cracked the comp 128v1 encryption scheme. [14:59.330 --> 15:03.350] But basically there's a lot of cool data that's stored in SIM cards. [15:03.510 --> 15:09.530] Even today, for example, the last 10 phone numbers dialed from a phone, even if you've deleted your call history. [15:10.250 --> 15:12.590] Sometimes sent and received SMSs are still stored. [15:13.450 --> 15:31.030] So even, you know, interestingly enough, even though SIM card cloning was only really popular in the late 90s, it became popular again because that was how iPhones were originally cracked, was to duplicate SIMs, but change a little bit of the information so you could use a different carrier than AT&T. [15:31.450 --> 15:42.910] So, but unfortunately when I looked online for SIM information, all of it was very focused on just either forensics, like really hardcore forensics information, or basically how to hack iPhones. [15:43.050 --> 15:49.090] So I wanted to sort of create a more generalized introduction to SIM cards and how to read that data off of SIM cards. [15:49.190 --> 15:58.010] And I was going to do that by building a very, very inexpensive SIM card reader and show how to do that in your own home and then run the free and open source software on your own computer. [15:58.010 --> 16:00.730] And from this point forward, you can turn off the house lights if that's okay. [16:00.910 --> 16:01.810] If not, we understand too. [16:03.030 --> 16:04.770] So I've got all my tools set up here. [16:05.010 --> 16:09.130] I've got my multimeter, my trusty multimeter, which will be used for testing the circuit. [16:10.530 --> 16:14.550] The fume sucker, which will be used to get rid of all the fumes from soldering. [16:15.270 --> 16:16.890] And my soldering iron. [16:17.830 --> 16:21.810] I also have a nice vise for holding the circuit board while I work on it. [16:21.850 --> 16:24.790] This is really useful, but you can use a third hand tool as well. [16:24.790 --> 16:27.010] So there's three parts of a SIM card reader. [16:27.270 --> 16:34.670] There's the power supply section, there's the oscillator section, and then there's the serial port and card interface section. [16:35.370 --> 16:40.190] So for the power supply, you'll need a 9-volt battery and a 9-volt battery holder. [16:40.250 --> 16:42.390] So we connect the battery up to the circuit board. [16:44.470 --> 16:46.670] A 1N4001 protection diode. [16:47.470 --> 16:49.110] And a 7805. [16:49.450 --> 16:53.430] 7805s come in two varieties, little mini version and big brother version. [16:53.550 --> 16:54.410] You can use either one. [16:55.530 --> 16:59.230] The power supply should also have an LED that'll indicate when the device is on. [16:59.370 --> 17:01.570] So an LED and a 1K resistor. [17:02.130 --> 17:08.770] And then to keep the power supply functioning well, a bypass capacitor is necessary. [17:09.730 --> 17:14.770] This one is a 100 microfarad capacitor, and this is a small ceramic capacitor. [17:14.890 --> 17:17.570] The second part of the circuit that we're going to build is the oscillator section. [17:17.830 --> 17:22.110] That's the part that generates the 3.57 megahertz signal that's sent to the SIM card. [17:22.290 --> 17:23.770] That lets it run at the correct baud rate. [17:24.210 --> 17:38.610] You'll need a 3.57 megahertz crystal, two 20 picofarad capacitors, a 1 megaohm resistor, a 2K resistor, and a 74HC04 NOT gate. [17:40.730 --> 17:43.350] You can also get a socket to put the gate into. [17:43.610 --> 17:44.810] It makes it fit nicely. [17:44.990 --> 17:49.490] The third part of the circuitry is the serial port and SIM card interface. [17:49.850 --> 17:53.430] Now the most important part here is to get a good SIM card holder. [17:53.430 --> 17:59.470] This allows you to put the SIM card in and lock it so you can create a good connection with it. [18:00.130 --> 18:03.570] And a female DB9 serial port connector. [18:03.950 --> 18:06.050] This is what you'll be able to connect to the computer. [18:06.330 --> 18:14.950] You'll also need two Zener diodes, anywhere between 3.6 to 6 volt is perfectly fine, and three 10K resistors. [18:15.130 --> 18:22.770] This part is what allows a 10 volt serial port to contact with a 5 volt SIM card reader safely. [18:22.770 --> 18:24.950] You'll also need an NPN transistor. [18:25.170 --> 18:25.790] Any kind will do. [18:25.970 --> 18:31.090] A SIM card has a bunch of contacts on the bottom that allows the SIM card reader to talk to it. [18:31.730 --> 18:37.930] Now there's eight or nine or 10 contacts here, but only the six middle ones are really important. [18:38.150 --> 18:39.830] This is what the SIM card looks like on the bottom. [18:40.770 --> 18:44.190] Now there's the six contacts, and in the middle there's one big contact. [18:44.350 --> 18:46.550] And that one big contact is connected to one of the side ones. [18:47.050 --> 18:48.370] That's the ground contact. [18:49.930 --> 18:51.810] That's used for power and signal ground. [18:52.550 --> 18:54.490] Underneath that is the programming pin contact. [18:54.730 --> 18:58.190] That's used by the manufacturer to program the SIM card when it comes out of the factory. [18:58.570 --> 18:59.930] We won't be using that pin though. [19:00.110 --> 19:01.690] We'll be using the serial I/O pin that's right beneath that. [19:03.410 --> 19:05.170] That's how the computer talks to the SIM card. [19:05.550 --> 19:08.170] On the other side is the clock pin. [19:09.410 --> 19:14.550] That's where the reader sends a clock signal to the SIM card chip to tell it what the correct baud rate is. [19:14.950 --> 19:25.510] Make sure to be using a 3.57 megahertz clock, which translates to a 9600 baud signal. [19:26.450 --> 19:28.170] Above that is the reset pin. [19:28.370 --> 19:31.350] That's how the reader says, hey, wake up, we're ready to talk to you. [19:31.570 --> 19:33.670] And above that is the five volt pin. [19:33.670 --> 19:35.670] That's how you send power to the SIM card. [21:12.430 --> 21:18.810] Open up the cell phone and remove the SIM card and put the phone to the side. [21:21.610 --> 21:29.510] Now turn over the SIM card reader and slide in the SIM card so that it locks in. [21:32.330 --> 21:33.910] Plug in the 9 volt battery. [21:35.590 --> 21:37.070] The green LED should be lit. [21:38.510 --> 21:40.270] Now connect up the serial port. [21:42.730 --> 21:43.850] Let's run the software. [21:44.210 --> 21:46.830] Select the serial port that the SIM card reader is connected to. [21:47.150 --> 21:49.110] For Windows, it's probably something like Comport 1. [21:52.210 --> 21:55.410] First thing we'll do is extract the saved SMSs from the SIM card. [21:55.690 --> 21:59.650] Now some phones don't overwrite old SIMs with zeros or FF. [21:59.870 --> 22:03.390] So you can actually extract deleted SMSs and undelete them. [22:03.990 --> 22:10.150] Every SMS message has the recipient, the sender, the message, and the timestamp. [22:10.150 --> 22:11.630] So you can see when it was received. [22:12.870 --> 22:14.530] Next we'll read the last dial numbers. [22:14.710 --> 22:17.170] These are the last 10 numbers that the cell phone tried to call. [22:19.030 --> 22:20.410] Next we'll read the phone book. [22:20.590 --> 22:24.090] Now this is all the contact and phone number information that's stored in the SIM card. [22:24.530 --> 22:27.910] Sometimes it's used as a backup and sometimes it's the primary phone book. [22:27.910 --> 22:32.950] Now it takes a long time to read the phone book because there's 250 entries in the SIM card contact data. [22:34.230 --> 22:36.350] Each contact has a name and a phone number. [22:36.670 --> 22:38.570] Finally, we're going to look up the SIM information. [22:38.770 --> 22:40.410] Now this is sort of low level information. [22:40.610 --> 22:44.950] The serial number or the last location the phone was used in, pin statistics, stuff like that. [22:45.530 --> 22:47.090] When you're done, you can just disconnect the reader. [22:47.690 --> 22:54.330] Finally, if you're interested in the low level protocol data, you should look through the debug window where you can see what kind of information was sent and received from the SIM card. [22:54.770 --> 22:56.810] Now let's say you wanted to clone a SIM card. [22:57.030 --> 23:01.350] Well, there's no way the SIM card is going to give up the unique identifier and the secret key. [23:01.510 --> 23:04.690] But what you can do is perform a known plain text attack. [23:04.930 --> 23:09.410] And that will hit the SIM card tens of thousands of times using software, which I have running here. [23:09.670 --> 23:11.110] And if it works out, you get the key. [23:11.410 --> 23:14.190] But most SIMs, it doesn't work on any longer. [23:14.390 --> 23:17.250] And also, it can disable some SIMs. [23:17.470 --> 23:18.990] So we're going to run the software. [23:19.110 --> 23:20.110] It takes about six hours. [23:20.350 --> 23:21.490] So let's give it a whirl. [23:35.650 --> 23:37.230] All right, so let's see how we made out. [23:37.690 --> 23:40.650] Looks like that we were able to correct the SIM card. [23:40.870 --> 23:44.050] No, all we would need to do is copy this information to a writable SIM. [23:44.250 --> 23:45.270] This project is done. [23:47.830 --> 23:49.410] All right, so that was the SIM card hacking. [23:57.030 --> 23:59.310] It's very hard to make electronics exciting. [23:59.470 --> 24:00.210] I don't know if we succeeded. [24:01.090 --> 24:01.510] We tried. [24:01.630 --> 24:02.590] We had some techno music. [24:02.830 --> 24:03.590] So, you know, what can you do? [24:04.070 --> 24:05.870] So the next part is payphone hacking. [24:07.790 --> 24:11.090] And the thing about payphones is they're all being decommissioned. [24:11.170 --> 24:12.190] They're pretty much going away. [24:12.310 --> 24:13.570] There's millions of them available. [24:14.110 --> 24:16.430] And as we looked around, we saw all these payphones. [24:16.430 --> 24:18.670] And we wanted to do something cool with it. [24:18.770 --> 24:20.510] And we also still have a red box. [24:21.070 --> 24:23.250] So, you know, we were like, what are we going to do with this red box? [24:23.390 --> 24:25.610] So the next clip. [24:25.830 --> 24:26.830] Should I talk with my little finger? [24:27.170 --> 24:27.490] What was that? [24:27.650 --> 24:28.090] A piece of paper? [24:28.850 --> 24:29.170] What? [24:29.330 --> 24:30.170] Remember I had a piece of paper? [24:30.810 --> 24:31.130] Yeah. [24:34.070 --> 24:39.870] So we decided to procure some payphones to do some projects with them. [24:39.870 --> 24:42.930] And you can probably talk a little bit about this further. [24:42.970 --> 24:44.570] So we're just going to fast-forward through the intro for this video. [24:44.770 --> 24:46.430] And so I'll just sort of explain it very quickly. [24:46.770 --> 24:49.190] But, you know, most of you are aware there's two... [24:49.190 --> 24:51.370] There's basically two kinds of payphones out there. [24:51.610 --> 24:54.090] There's the standard telco-style payphones. [24:54.130 --> 24:55.070] And there's COCOTs. [24:55.630 --> 24:57.570] And those are the coin-owned... [24:57.570 --> 24:59.330] Customer-owned coin-operated telephones. [24:59.510 --> 25:00.150] And those are... [25:00.150 --> 25:02.310] Actually have real computers inside of them. [25:02.390 --> 25:04.210] And when you pick up the phone, it's a fake dial tone. [25:04.470 --> 25:09.210] And all the calculation about how much money to put in, and whether it's time to hang up or if it's a collect call. [25:09.350 --> 25:11.470] All that is done inside the payphone. [25:12.830 --> 25:29.390] But telco payphones, which have had pretty much the same design for like 30 or 40 years now, because they didn't have microcontrollers, microprocessors when they were first invented, all of the thinking and the hard work of what money is owed and whether coins have been put in have been done on the switch side, [25:29.450 --> 25:30.510] right, at the central office. [25:30.890 --> 25:33.750] So what that means is that these payphones are really dumb. [25:33.890 --> 25:36.170] There's actually no electronics in them. [25:36.170 --> 25:38.010] Very, very little electronics in them. [25:38.170 --> 25:42.990] And almost all the control is done using really strange voltages that occur on the switch side. [25:43.210 --> 25:51.370] So although we'll show how you can modify payphone for home use, all the cool stuff that payphones do, you can't get out of a home phone line. [25:51.470 --> 25:58.730] You just can't get it out of the voltages that come from a home phone line, because it's not a special phone line switch. [26:00.070 --> 26:05.370] But, you know, we got this payphone and we decided, you know, this stuff is so cool. [26:05.510 --> 26:15.930] We opened it up and I'd never actually seen the inside of a payphone and so I thought, well, I used to hack payphones from the outside, but I thought it'd be cool to hack them from the inside instead. [26:16.390 --> 26:24.490] So we kind of split up the project into three parts or three or four parts and we show some really cool stuff you can do with payphones, especially the telco style. [26:25.430 --> 26:29.030] So let's just play the video and hopefully it'll be self-explanatory. [26:29.210 --> 26:30.350] And you can play with this payphone. [26:30.450 --> 26:32.150] We'll have it at the vendor table downstairs. [26:32.150 --> 26:37.210] It's not plugged in here, but we'll have a void box so you can hack it. [26:37.350 --> 26:38.330] It's going to look similar. [26:40.530 --> 26:48.070] What you want to look for is bell logos, bell names, anything that says, you know, the local telephone company on it. [26:48.330 --> 26:51.810] Every brand of payphone has its own T key that's used to open it up. [26:52.510 --> 26:55.230] Put it in the side and turn. [26:55.730 --> 27:00.750] Move the handset and pull the front off. [27:01.690 --> 27:07.250] Be careful because inside there's a plug from both halves. [27:08.630 --> 27:11.070] Connecting a payphone for home use is pretty easy. [27:11.430 --> 27:20.650] First you'll need a telephone wire that has telephone spade lugs on one end and standard screwdriver. [27:21.010 --> 27:26.170] Feed the telephone spade lugs through the back of the phone. [27:26.950 --> 27:37.710] Then connect the red wire, which is the ring, to this terminal block marked R. [27:41.130 --> 27:48.430] Second, connect the green spade lug, which is the tip to the terminal block marked T. [27:55.160 --> 28:00.740] Finally, take the black and yellow wire, which are not going to be used, and tie them to the ground connector. [28:02.580 --> 28:09.060] The coin counting circuitry has to be jumpered so that the phone doesn't expect a coin to be inserted before it can make a call. [28:09.340 --> 28:15.280] Now that's actually already been done here by jumpering pin 5 and pin 8 on this plug. [28:15.660 --> 28:18.760] Otherwise, you can just solder a piece of wire in to connect the two. [28:19.920 --> 28:24.300] Now simply plug the payphone into your home phone line or, in this case, a VoIP box. [28:26.680 --> 28:28.160] Now's the time to test the wiring. [28:28.480 --> 28:29.100] It's pretty easy. [28:29.300 --> 28:30.400] Just call the phone from another line. [28:41.960 --> 28:43.880] There are many distinct parts to a payphone. [28:44.280 --> 28:48.280] On the left, there's the coin sorting mechanism, which detects valid currency. [28:48.700 --> 28:51.100] And then below that is the coin hopper. [28:51.220 --> 28:54.160] That's where coins are stored while the payphone makes a phone call. [28:54.500 --> 28:56.340] And then this is the coin relay. [28:56.500 --> 29:01.320] This controls whether coins in the hopper go into the coin box or into the return chute. [29:02.060 --> 29:12.820] On the right side, there's the bell, the phone line terminal block, the coin tone oscillator, and the connectors and jumpers for the two halves of the payphone. [29:13.340 --> 29:15.180] Here's where the totalizer would live. [29:15.340 --> 29:19.060] Now, unfortunately, the totalizer was ripped out of this payphone before we procured it. [29:19.160 --> 29:28.000] On the other half of the payphone, there's the handset switch hook detector, the tone pad, which is on the back, and the DTMF encoder and terminal block. [29:28.180 --> 29:34.620] To remove the coin assembly, first flip this latch, then reach in and push on the wire ring. [29:35.200 --> 29:36.760] And this part just comes out. [29:38.780 --> 29:46.100] To open up the coin assembly, just flip it open, and then these magnets also flip open. [29:46.300 --> 29:50.200] When a coin is inserted into the payphone, it travels down this chute. [29:50.500 --> 29:54.140] Now, in this case, a quarter will pass by the quarter separator. [29:54.340 --> 30:00.380] Only if it's the correct size and weight will it rotate the separator and cause it to pass past this magnet. [30:00.680 --> 30:11.300] This magnet sets up an eddy current inside the conductive metal of the coin, which causes it to slow down a little bit and bypass this chute and continue into this one, where the coin is accepted. [30:14.980 --> 30:24.420] The coin then drops into the hopper, where the payphone waits until the switch tells it whether to put the coin in the coin box or return it into the return chute. [30:24.640 --> 30:28.240] Now, this payphone is ready to make phone calls from home, but that's not going to be much fun. [30:28.440 --> 30:31.780] What I want to do is modify this payphone so it requires coins to make a phone call. [30:32.460 --> 30:35.740] Since there's no totalizer, I'm going to have to add a sensor to detect coins. [30:35.880 --> 30:38.440] I'm going to put one here on this little flapper. [30:38.980 --> 30:41.260] The sensor I'm going to use is a brake beam sensor. [30:41.540 --> 30:46.360] There's an emitter and a detector, and when an object goes in between, the sensor goes off. [30:46.660 --> 30:48.520] Cut a flap out of a piece of card. [30:51.850 --> 30:54.730] The flap will be glued onto the hopper trigger right here. [30:55.830 --> 30:57.750] Glue the flap onto the hopper trigger. [30:58.890 --> 31:00.210] And now it's time to solder. [31:00.470 --> 31:02.250] The first part is the fast line. [31:28.370 --> 31:32.030] Ah, what a colorful output of the waiting document. [31:32.030 --> 31:33.110] Just wait a couple more seconds... tag an auto switch by the holder. [31:33.110 --> 31:33.130] And I keep going straight to the holder, so I'll break it down. [31:33.130 --> 31:35.390] I won't let them Affairs back up, I'll let them see. [31:35.910 --> 31:36.290] Start trying to do nothing, because this is a hard tool. [31:36.990 --> 31:40.810] So, this is the coin detector and phone controller that we started with. [31:41.690 --> 31:46.170] As a power supply, I'm using four AA batteries connected to the battery pack. [31:47.270 --> 31:48.630] This is the power supply. [31:48.810 --> 31:53.430] It's just a capacitor just to regulate the power and a little indicator LED to tell me it's on. [31:54.350 --> 32:01.230] Then I've hooked up the sensor that will detect when a coin has gone down the slot. [32:02.410 --> 32:11.770] That's connected to a latch which will take the small pulse that comes from the sensor and convert it into a steady voltage, which then controls the telecom relay. [32:12.090 --> 32:16.490] That's a relay that's specifically designed to control the high telecom voltages. [32:16.490 --> 32:17.790] It'll work off of five volts. [32:17.910 --> 32:18.350] That's perfect. [32:19.270 --> 32:22.390] So, testing the sensor by putting a card in front. [32:22.970 --> 32:25.630] Now I'm going to glue the sensor into the payphone. [32:32.240 --> 32:34.020] Now I'm going to glue the other side of the sensor. [32:35.860 --> 32:38.960] Make two wires with spade lugs on the end. [32:44.440 --> 32:50.800] Connect one of the spade lugs to the phone line ring and the other spade lug to the payphone ring. [32:57.960 --> 33:00.900] Now plug in those two jumper wires into the relay. [33:01.660 --> 33:03.620] Now click the coin relay open. [33:05.300 --> 33:07.240] Now it's time to test our system. [33:07.560 --> 33:10.720] Turn on the battery pack and pick up the phone. [33:11.900 --> 33:13.260] There won't be a dial tone. [33:13.600 --> 33:19.940] Now press on the coin hopper trigger so that the sensor is broken and you'll hear a dial tone. [33:22.240 --> 33:23.860] Now I'm going to put the payphone back together. [33:24.300 --> 33:26.300] Insert the coin validator, close it up. [33:26.660 --> 33:30.060] Now nobody can make a phone call on my Skype payphone unless they put in a quarter. [33:30.580 --> 33:34.300] Now put in the coin validator and make sure to be careful of the sensor you've placed in. [33:36.380 --> 33:45.560] Finally, wire up a bump sensor between the power from the battery pack and the circuit board so when the switch is depressed, power to the board gets cut. [33:49.040 --> 33:52.960] Glue the sensor so when the phone is on hook, the switch is depressed. [33:53.440 --> 33:58.720] To make wiring easier, I'm going to crimp on some lugs onto the switch contacts. [34:06.360 --> 34:10.260] Thread these wires through the small hole in the payphone bottom. [34:16.400 --> 34:18.260] And thread the power connector up. [34:22.030 --> 34:25.890] This payphone didn't come with a coin box so I'm going to use a blue cup instead. [34:26.910 --> 34:28.010] Just put it in the back. [34:29.030 --> 34:33.110] Finally, stash the power supply and the circuit board right in front. [34:34.730 --> 34:36.350] Put the front of the coin box in. [34:37.290 --> 34:38.890] Unlock it again with the T key. [34:40.990 --> 34:41.870] Slide it on. [34:44.960 --> 34:45.440] Unlock. [34:46.100 --> 34:47.320] Now close up the payphone. [34:47.820 --> 34:48.060] Oops. [34:49.740 --> 34:50.800] It's really heavy. [34:59.660 --> 35:00.540] No dial tone. [35:01.560 --> 35:02.320] Insert a quarter. [35:03.080 --> 35:04.060] Now I've got a dial tone. [35:04.200 --> 35:04.840] You can make a phone call. [35:05.000 --> 35:05.800] This project is done. [35:08.460 --> 35:10.860] So my pay, payphone project works pretty well. [35:10.860 --> 35:13.480] But I want to add a little bit of old school charm to it. [35:13.860 --> 35:17.680] Instead of the coin going directly into the coin box when you put it in, I want it to sit in the hopper. [35:17.860 --> 35:25.160] And then when the phone is hung up, the coin relay will activate and the coin will drop into the coin box making that nice kachink sound. [35:25.900 --> 35:27.540] Time to crack open the payphone again. [35:30.960 --> 35:32.940] This is that coin relay that we clipped open. [35:33.760 --> 35:35.380] Now I'm going to unclip it. [35:36.000 --> 35:38.300] To actuate this relay I need 130 volts. [35:38.620 --> 35:43.000] But I don't really have 130 volts kicking around here because this isn't hooked up to a payphone phone line. [35:43.560 --> 35:47.640] The phone line can generate 48 volts, but it doesn't have enough current to drive the relay. [35:47.640 --> 35:51.740] So I'm going to have to build my own DC power supply from the battery pack in the coin box. [35:52.760 --> 35:55.480] First thing I'll do is build the high voltage power supply. [36:23.540 --> 36:29.160] This is a basic DC-DC boost converter based on the LT-1073 chip. [36:29.300 --> 36:30.960] This chip actually does almost all of the work. [36:30.960 --> 36:37.340] All that's required is an inductor, a shock key diode, and some capacitors for the input and output. [36:37.560 --> 36:39.460] And it's just to set the output voltage. [36:40.020 --> 36:42.320] The input battery pack power comes in here. [36:42.800 --> 36:45.640] And the output 30 volts comes out of these green wires. [36:46.800 --> 36:50.560] Before wiring this up to our existing circuit, I'm going to test the voltage. [36:50.620 --> 36:54.700] Just measure with a multimeter the voltage between the two green wires. [36:55.000 --> 36:56.460] It should be around 30 volts. [36:56.460 --> 36:59.200] Now is a good time to test the DC-DC boost converter. [37:00.180 --> 37:05.180] Connect up the converter to the switch so that it's only powered when the phone is on hook. [37:06.120 --> 37:08.220] Remove the spring from the coin relay. [37:08.480 --> 37:13.880] And then try testing the two prongs to the coin relay and make sure it activates. [37:14.720 --> 37:17.960] Plug in the power so it's only activated when the phone is on hook. [37:18.420 --> 37:20.560] Remove the coin relay return spring. [37:20.760 --> 37:22.820] This will make it easier to activate with lower voltages. [37:27.780 --> 37:35.460] With the coin and the hopper, connect the 30 volts output to the two connectors for the relay, G and this three here. [37:36.560 --> 37:37.780] The relay should activate. [37:38.920 --> 37:43.060] Once it's been verified to work, attach the prongs permanently. [37:44.560 --> 37:48.180] Connecting them in one way makes the coin go into the coin box. [37:48.460 --> 37:51.040] Connecting them in the other way, the coins will go into the return chute. [37:53.340 --> 38:00.560] One of the nice things about the Western Electric Payphone designs is that there's a little read relay right where the coin detector is. [38:00.740 --> 38:07.240] That means that once the coin relay activates, this disconnects and the relay automatically opens. [38:07.580 --> 38:09.360] I'm going to cut this board down a little bit. [38:09.460 --> 38:10.500] This will make it fit nicer. [38:12.100 --> 38:14.660] Then I can use the extra scrap for another project. [38:17.260 --> 38:19.240] Then put the circuit board in a little baggie. [38:19.360 --> 38:23.480] This will protect the high voltages from touching some other part of the circuit board. [38:25.080 --> 38:29.960] Okay, put everything back in the coin box and we're going to close up the payphone and test this last mod. [38:38.870 --> 38:39.730] Time to try it out. [38:40.270 --> 38:42.390] Pick up the handset and deposit a coin. [38:44.150 --> 38:45.530] Now the coin is in the hopper. [38:46.190 --> 38:48.950] Hang up, the coin will be deposited in the coin box. [38:51.950 --> 38:53.610] So I've got this payphone. [38:53.810 --> 38:55.050] It's been modified for home use. [38:55.230 --> 39:01.370] And I've taken it and reverse engineered it and made it so that it now requires coins to make a phone call. [39:01.570 --> 39:05.110] And I've also added the coin hopper and coin relay activation. [39:05.510 --> 39:07.850] But there's one more hack I want to do on this phone. [39:08.010 --> 39:13.170] But before I get into that, it's important to understand how these dumb payphones keep track of how much money has been inserted. [39:13.350 --> 39:15.410] In this payphone, the totalizer has been taken out. [39:15.410 --> 39:26.330] It normally sits here and it has little arms that stick into the coin validator so that when a coin falls through, it triggers and sets off the coin tone oscillator, this pink box here. [39:26.890 --> 39:30.990] The coin oscillator is a passive oscillator that generates 2200 Hz and 1700 Hz. [39:31.290 --> 39:33.890] You can trigger the coin tone oscillator pretty easily. [39:34.230 --> 39:40.650] Connect one diode to pin 7 and another diode to pin 4 of J2. [39:41.450 --> 39:46.210] Clip pin 7 to the tip and pin 4 to the ring. [39:48.790 --> 39:52.510] Now, when a quarter is inserted into this payphone, the totalizer detects that. [39:52.710 --> 39:55.750] And it triggers the coin tone oscillator for a quarter. [39:55.950 --> 39:56.950] It triggers it five times. [40:00.740 --> 40:04.360] Now, that tone goes down the phone line and is detected by the switch on the other side. [40:04.360 --> 40:12.480] The switch looks up the current call rates and determines how much money has been deposited and how much money is owed and asks the user to please deposit more money if necessary. [40:12.960 --> 40:30.640] In the late 80s, some clever person either read the bell systems manual or deduced how payphones work from observation and determined that if you played those 2200 plus 1700 Hz tones into the microphone, it would go down the phone line and the switch on the other side would be fooled into thinking the totalizer and coin tone oscillator made those tones. [40:30.640 --> 40:32.640] And thus was red boxing born. [40:33.240 --> 40:42.200] Red boxing became much more popular when it was noticed that the dual tone multi-frequencies from the coin tone oscillator are directly proportional to the tones generated when you hit the star key on a phone. [40:42.620 --> 40:47.280] And those tones are directly proportional to whatever crystal oscillator is driving the DTMF encoder chip. [40:47.480 --> 40:52.420] So to make these special coin oscillator tones, you don't need a coin tone oscillator box. [40:52.420 --> 40:56.420] You could just use a DTMF generator like this old RadioShack tone dialer. [40:56.520 --> 40:57.800] This one is 16 years old. [40:58.340 --> 40:59.400] All you have to do is change the crystal. [41:00.820 --> 41:07.540] So open it up and swap out the old crystal for this, a 6.5536 MHz crystal. [41:08.040 --> 41:12.680] Now the dialer will emit the same tones necessary when you hit the star key. [41:14.260 --> 41:22.100] Now, due to various anti-fraud measures, the emergence of code cots, and AT&T discontinuing their payphone line service, red boxing is a rarity. [41:22.300 --> 41:23.720] It's pretty much impossible to do anymore. [41:24.000 --> 41:26.960] That's a real shame, because I've got one of these red boxes and I really like to use it. [41:27.240 --> 41:31.720] So what I'm going to do is I'm going to modify this payphone so that I can red box out instead of putting coins in it. [41:31.960 --> 41:35.000] You don't have to build a circuit to protect the red box tones when it contains the microphone. [41:36.020 --> 41:38.840] To do that, I'm going to use a DTMF decoder chip. [41:38.840 --> 41:45.340] These are the chips that were used in old voicemail systems, like pressing one or two or three would open a mailbox or close it. [41:45.760 --> 41:51.360] I'm going to use this chip, but instead of using the crystal that's supposed to be used with it, I'm going to change it to a different crystal. [41:51.440 --> 41:53.220] This is the same one used to hack red boxes. [41:53.600 --> 41:56.360] So now both of them are listening for the same frequency tones. [41:56.780 --> 41:58.680] Now all to do is detect one of the star keys pressed. [41:58.840 --> 42:00.240] That's the same as a red box tone. [42:17.760 --> 42:20.880] Okay, now is a good time to test the red box tone detector. [42:21.120 --> 42:23.020] Here's the circuitry for the red box detector. [42:23.300 --> 42:27.660] Now I've got the DTMF decoder with the new crystal, so it can detect red box tones. [42:28.260 --> 42:34.220] And I've got this selector latch, and that will make sure that only when the star key is pressed will the latch go high. [42:34.220 --> 42:36.100] And here's a little indicator LED. [42:36.280 --> 42:38.780] This will blink when it detects a red box tone. [42:38.900 --> 42:39.780] That's very useful for debugging. [42:40.040 --> 42:45.460] To connect up to the handset and listen to the audio coming in from the microphone, I'm going to jack it into this terminal block. [42:45.940 --> 42:54.360] Now this is the reference ground, number 11, and this red wire is from the handset, and that comes from the microphone, so that's going to be our audio input. [42:54.740 --> 43:01.440] I've disconnected the ring line from our relay and jumpered it just so we can do this test without having to worry about the relay turning on and off. [43:01.440 --> 43:04.100] Okay, pick up the handset, and there will be a dial tone. [43:04.380 --> 43:07.480] And you'll see that this board is lit, but the green LED is not on. [43:08.100 --> 43:09.300] Now red box. [43:10.220 --> 43:13.220] You'll see that the green LED lights up because it detected the star. [43:14.740 --> 43:15.980] So that's our system. [43:16.240 --> 43:18.360] The system seems to work, but there's one problem. [43:18.680 --> 43:32.540] Now because the payphone is designed to be coin first, that is, we don't connect the phone line until we get money or a red box signal, there's no power to the microphone, so the circuit can't actually listen in on the microphone because there's no power. [43:32.980 --> 43:39.140] But we're going to solve this pretty easily by biasing the handset ourselves by using a 5-volt power supply. [43:39.480 --> 43:44.400] Luckily the internal power supply for the handset is supposed to be 5 volts, so it's kind of a lucky coincidence. [43:44.400 --> 43:50.120] First I'll connect my audio input to the circuit, that'll come from here, the handset ring. [43:52.820 --> 43:56.260] Now I'll connect the ground reference prong, that goes up here. [43:59.750 --> 44:04.950] Now I'm going to connect the bias power to the handset, that goes into the handset tip. [44:10.060 --> 44:18.300] Now this telecom relay is a double throw, that means there are actually two switches inside, and I'm going to use that second switch to connect and disconnect that bias power. [44:18.860 --> 44:23.520] So only when we don't have the phone line connected here, will there be power to the handset. [44:23.640 --> 44:26.640] This way, our 5 volts won't compete with the phone line 5 volts. [44:26.800 --> 44:28.740] One more thing to do, and that's close up the payphone. [44:29.000 --> 44:31.340] Okay, project's done, I'm ready to use it. [44:32.160 --> 44:35.680] Pick up the phone, no dial tone, get my handy red box. [44:37.580 --> 44:39.040] Now I'm ready to call some comps. [44:50.760 --> 44:51.760] Okay, so that's our video. [44:56.250 --> 45:05.990] What I like about this video is the way it's displayed here, it's kind of like Hong Kong style, like it's a little bit off, so we're going to put like Chinese subtitles in. [45:06.230 --> 45:09.550] And then we're going to have a fight scene in the middle where I like punch his head off. [45:09.730 --> 45:11.350] Yeah, so this is all shot in HD. [45:11.510 --> 45:16.670] You can download the one gigabyte like, you know, actual size version, you know, if you have a big enough screen. [45:17.890 --> 45:24.030] And we hope to do one of these every so often about some of the older technologies, kind of with a new twist. [45:24.150 --> 45:25.630] And newer technologies too, not just older stuff. [45:25.750 --> 45:26.510] Yeah, and some newer things. [45:26.510 --> 45:28.670] It's a special hope memorial edition. [45:29.450 --> 45:39.970] Yeah, so, you know, using this video and all of the source code, schematics, and everything we put on citizenengineer.com, you get a payphone and do all of these projects, and you can build one of these SIM card readers. [45:40.130 --> 45:41.430] So we have time for questions. [45:42.250 --> 45:44.450] We have actually 10 minutes. [45:45.090 --> 45:45.150] Perfect. [45:45.150 --> 45:46.330] So if you have questions, hop up. [45:46.670 --> 45:47.430] If not... [45:48.150 --> 45:49.130] You have to go to the microphone. [45:53.550 --> 45:57.170] Where would you procure one of these telephones? [45:57.290 --> 45:58.310] Well, there's some in the lobby here. [45:58.310 --> 45:58.970] Do you have a truck? [46:01.010 --> 46:09.050] Because there's 2.4 million payphones out there, but there's not any more 2.4 million customers for payphones, they're getting uninstalled. [46:09.190 --> 46:12.290] If you look around New York, you'll see booths and the payphone's been taken out. [46:12.290 --> 46:14.650] And those aren't stolen, they've just been decommissioned. [46:15.050 --> 46:22.290] AT&T has been losing money on payphones for so long, they were required to keep providing payphone service due to the bell breakup. [46:22.410 --> 46:23.290] You can look at all this stuff online. [46:23.430 --> 46:25.290] So eBay, Craigslist... [46:26.270 --> 46:31.370] But recently they were freed from maintaining them, and so now they're uninstalling them and selling them. [46:31.530 --> 46:36.590] On Craigslist, I have an RSS feed that just says Payphone, and it's for everywhere. [46:36.830 --> 46:40.410] And you get really weird stuff, obviously, from Craigslist and Payphone. [46:42.010 --> 46:43.290] They want about $50. [46:43.910 --> 46:44.170] Yeah. [46:44.350 --> 46:45.510] I mean, they're pretty cheap nowadays. [46:45.870 --> 46:47.650] And people have warehouses full of these. [46:47.830 --> 46:51.070] So you just... believe it or not, if you look for them, you'll actually find a lot. [46:51.690 --> 47:00.050] Just make sure if you want to do this hacking to get one of these old-school 1C2 or 1D2 telco payphones, because again, if it's a cocot... [47:00.050 --> 47:05.250] I know you can modify for the home use, but it's just more complicated, because it's basically just a big circuit board. [47:05.250 --> 47:07.430] So make sure when it's open, it's like mechanical. [47:08.130 --> 47:10.270] It's all like analog parts, electromechanical stuff. [47:10.550 --> 47:10.970] All right. [47:11.130 --> 47:11.410] Thank you. [47:15.320 --> 47:15.840] Hi. [47:16.000 --> 47:24.400] I've been noticing with newer and newer technologies, especially with like building computers and stuff, motherboards are actually phasing out the serial port. [47:24.740 --> 47:25.000] Yeah. [47:25.540 --> 47:31.260] And I was wondering what are some of the alternatives, because some of your projects actually have serial port entries into them. [47:31.260 --> 47:37.680] Well, there's still a lot of computers that do have serial ports, but luckily you can get a USB to serial converter for like $10. [47:38.860 --> 47:42.120] I also, I mean, it's just doing USB on board is a little difficult. [47:42.440 --> 47:48.300] So I went with serial and then it's like, oh, if you have a serial port, this is a $15, $12 adapter that you use. [47:48.360 --> 47:49.320] You can get it at RadioShack. [47:49.460 --> 47:51.020] I mean, that's not too difficult. [47:52.280 --> 47:52.680] All right. [47:52.760 --> 47:52.920] Thanks. [47:53.060 --> 47:59.300] One of the things that a lot of our kits that make and some of the kits that Lamar makes, they have a serial port to communicate with them. [47:59.300 --> 48:00.440] And hobbyists like that. [48:00.580 --> 48:03.140] But as you were saying, serial ports, things are changing. [48:03.340 --> 48:04.840] I mean, it's not a parallel port. [48:05.040 --> 48:09.040] I mean, people, serial ports are still like not completely obsolete. [48:09.360 --> 48:16.220] So one of the things we're probably going to do is have part of a kit, the USB part already assembled, because that's usually surface mount. [48:16.400 --> 48:18.960] And then beginners can just do all the rest with through holes. [48:19.060 --> 48:22.460] So that's something we're doing on the kit side with electronic manufacturers. [48:22.660 --> 48:24.640] You know, we don't have, we don't have control. [48:24.760 --> 48:27.400] They still need to do like USB to serial. [48:30.300 --> 48:32.280] You mentioned Arduino a bit earlier. [48:34.000 --> 48:38.220] There's something called wiring, which is like the older brother, as it were, of Arduino. [48:38.220 --> 48:40.880] Would you ever consider making projects for that? [48:41.020 --> 48:42.000] Because I mean, we've got some... [48:42.000 --> 48:45.660] I think wiring is really awesome, but it's just much more expensive. [48:45.660 --> 48:52.760] And I like the simplicity and low cost and near commodification nearly of Arduino hardware. [48:52.920 --> 48:55.200] That's why I've been focusing on that. [48:55.580 --> 48:57.560] Many wiring boards, I think, are about $100. [48:58.220 --> 49:00.460] That's three times as much as an Arduino, so... [49:00.460 --> 49:03.540] You still get about 50 pins and two serial ports. [49:03.760 --> 49:08.140] Yeah, but I found that a lot of beginners projects, they don't need 50 pins. [49:08.260 --> 49:10.880] They're like, I want to blink an LED when the doorbell's pressed. [49:10.880 --> 49:13.740] So like, this allows them to do something simple like that. [49:13.880 --> 49:14.700] That's the only reason. [49:14.920 --> 49:19.540] But wiring is excellent and definitely a good choice to step up to. [49:20.320 --> 49:21.160] Cool, thanks. [49:24.220 --> 49:26.060] What about dialing into the payphone? [49:27.740 --> 49:32.460] So at this time, this payphone doesn't allow dialing in, but it's actually really, really easy. [49:32.940 --> 49:36.420] We just decided it didn't make much sense for me to do it on video. [49:36.740 --> 49:41.220] But basically, a full wave rectifier and SCR and a couple of resistors. [49:41.460 --> 49:47.980] And basically, when it gets the 90 volts on the ring voltage, that sets up the SCR and connects the phone line. [49:47.980 --> 49:50.840] So you don't have to put in a coin to make a phone call. [49:51.020 --> 49:51.580] Thank you. [49:52.040 --> 49:52.820] Or get a phone call. [49:52.940 --> 49:54.940] You could build this and do a video and send it to us. [49:54.940 --> 49:58.160] I mean, I have a link, I'm going to have a link on the web page to how to do that. [49:58.320 --> 50:01.820] But we decided like, you know, this was enough payphone hacking. [50:03.040 --> 50:06.220] How did you get the information for the SIM card output? [50:07.700 --> 50:09.540] The information is on citizenengineer.com. [50:09.880 --> 50:13.620] Did you just like basically interpret it on your own or is it documented? [50:13.680 --> 50:17.700] If you wait like 10 minutes until after our talk is done, it'll definitely be there. [50:17.940 --> 50:20.660] But we can't right now because we're doing a talk right now. [50:20.660 --> 50:22.220] We have to get online and release the talk. [50:22.220 --> 50:23.780] We're using the Wi-Fi so I can't get to the website. [50:24.020 --> 50:24.060] Yeah. [50:24.440 --> 50:25.700] We have to release the files. [50:25.940 --> 50:26.320] Tragic. [50:27.340 --> 50:27.720] Okay. [50:27.940 --> 50:29.540] And I think we are officially out of time. [50:29.820 --> 50:31.100] Well thank you guys, you can download this later. [50:31.340 --> 50:31.720] Yay. [50:39.670 --> 50:40.050] Hello. [50:40.050 --> 50:40.170] Hello!