WEBVTT

00:00:00.280 --> 00:00:07.000
did you know that Apple a $3.5 trillion

00:00:04.000 --> 00:00:09.040
company is only around due to an illegal

00:00:07.000 --> 00:00:14.679
back alley product back in the early 1970s Apple co-founders Steve Jobs and

00:00:11.639 --> 00:00:17.320
Steve wnac constructed a device called a

00:00:14.679 --> 00:00:22.279
blue box that essentially hacked phone systems allowing the user to make free

00:00:19.800 --> 00:00:27.160
long-distance calls a huge deal at the time as it wasn't uncommon to have to

00:00:24.320 --> 00:00:31.240
pay upwards of $3 a minute for calls across state lines the blue box was a

00:00:29.519 --> 00:00:35.760
result of a discovery that phone connections could be manipulated by

00:00:33.120 --> 00:00:43.200
playing certain sounds into a phone's handset a process called

00:00:39.800 --> 00:00:46.640
freaking to be more specific a tone of

00:00:43.200 --> 00:00:48.840
2600 Hertz which sounds like this was

00:00:46.640 --> 00:00:53.719
used by phone companies as a control signal that a certain line was now free

00:00:51.800 --> 00:00:59.239
typically because one of the callers had hung up but in the late 1950s a blind

00:00:56.719 --> 00:01:03.519
child named Joe Andia discovered a similar form of freaking accidentally

00:01:01.559 --> 00:01:08.680
while whistling into a phone that was playing a recorded message because our

00:01:06.080 --> 00:01:13.000
friend Joe had Perfect Pitch he was able to recreate this Behavior to make calls

00:01:10.840 --> 00:01:17.680
drop without hanging up the phone essentially manipulating the phone's

00:01:14.640 --> 00:01:19.600
backend systems from the user interface

00:01:17.680 --> 00:01:24.079
sort of like people on Twitter telling AI Bots to ignore all previous

00:01:21.799 --> 00:01:28.759
instructions a community started to emerge around phone freaking and

00:01:25.840 --> 00:01:32.799
eventually the blue box built upon Joe's Discovery to democ TI longdistance

00:01:31.040 --> 00:01:36.840
calling or cheat the phone companies out of Revenue depending on your perspective

00:01:35.000 --> 00:01:40.840
here's how it worked the user of the blue box would dial a toll-free 1800

00:01:39.320 --> 00:01:44.719
number to ensure they wouldn't be charged for the call when it heard the

00:01:42.640 --> 00:01:49.399
phone ring on the other end the blue box would play that 2600 HZ tone into the

00:01:47.399 --> 00:01:54.159
phone's handset which would trick the system into thinking the caller had hung

00:01:51.920 --> 00:01:59.360
up before anyone answered the line was marked as being free but the caller

00:01:56.479 --> 00:02:03.560
using the blue box was still on the line the blue box would then send the tones

00:02:01.600 --> 00:02:07.280
that corresponded to the number the user actually wanted to reach since the line

00:02:05.399 --> 00:02:11.400
was still active and voila free longdistance calling not a bad deal

00:02:09.119 --> 00:02:16.360
considering they were sold for 170 bucks each but no more than 100 of them were

00:02:13.920 --> 00:02:20.920
ever made because they were so rare one of them ended up selling at auction in

00:02:18.360 --> 00:02:26.760
2017 for $125,000 similar in price to the new

00:02:23.480 --> 00:02:28.480
iPhone 16 Pro with 2 TB of storage of

00:02:26.760 --> 00:02:32.400
course phone companies became wise to the blue box especially after a rather

00:02:30.519 --> 00:02:36.480
anti-establishment magazine ran an article with instructions on how to

00:02:34.440 --> 00:02:39.440
construct a similar device yourself at home we'll tell you about how the phone

00:02:38.200 --> 00:02:43.519
companies tried to put an end to freaking as well as how the freaking

00:02:41.360 --> 00:02:49.280
Community countered their counter right after we thank MSI their magx 870

00:02:47.040 --> 00:02:54.800
Tomahawk Wi-Fi motherboard is built for the most intense use cases be it AAA

00:02:52.360 --> 00:02:59.080
gaming or triple overtime grinding it comes loaded with four m.2 slots built

00:02:57.159 --> 00:03:04.560
in Wi-Fi 7 capabilities and supports ryzen 9 ,000 8,000 and 7,000 processors

00:03:02.840 --> 00:03:10.200
your absolutely baller builds call for a motherboard that can support them so

00:03:06.599 --> 00:03:12.480
check out msi's magx 870 Tomahawk Wi-Fi

00:03:10.200 --> 00:03:17.640
using our link today the main countermeasure against phone freaking is

00:03:14.159 --> 00:03:20.480
called signaling System 7 and I use the

00:03:17.640 --> 00:03:24.640
present tense is because it's actually still around today even though it was

00:03:21.879 --> 00:03:29.480
rolled out in the early 1980s the basic idea behind ss7 is simply to put the

00:03:27.519 --> 00:03:34.000
control signals on a separate line so they be manipulated by sounds played

00:03:31.280 --> 00:03:38.920
into the phone itself and while ss7 was reasonably effective at stopping that

00:03:35.840 --> 00:03:40.599
2600 htz attack it couldn't stop every

00:03:38.920 --> 00:03:45.239
kind of attack especially as phone technology continued to evolve a later

00:03:43.200 --> 00:03:50.319
common way to freak the phone network for free long-distance calls was to

00:03:47.280 --> 00:03:53.040
exploit the system of calling cards used

00:03:50.319 --> 00:03:56.319
by smaller carriers in the mid1 1980s back then it was common to have to dial

00:03:54.640 --> 00:04:01.640
a special local number owned by the phone company and then enter the code

00:03:59.079 --> 00:04:06.079
off a page card which let the network know you were authorized to make a

00:04:03.760 --> 00:04:09.879
long-distance call only then could you dial the number you were trying to

00:04:07.400 --> 00:04:14.120
connect to the problem for the phone companies was that the codes on these

00:04:11.560 --> 00:04:18.799
cards were quite short meaning it was easy for PCs to quickly guess lots of

00:04:16.959 --> 00:04:23.479
different combinations and try those combinations using a modem lots of codes

00:04:21.919 --> 00:04:27.960
were found this way and subsequently shared to the point where long-distance

00:04:25.639 --> 00:04:33.240
companies were losing a half billion dollars a year to this form of Brute

00:04:30.039 --> 00:04:35.639
Force freaking by 1987 this scam was

00:04:33.240 --> 00:04:40.199
very popular among college students in fact over 2500 of them were busted in a

00:04:38.080 --> 00:04:44.759
drag net but it was impossible for the phone companies to track down everyone

00:04:42.479 --> 00:04:47.960
who did this this form of freaking only disappeared when phone companies

00:04:46.039 --> 00:04:53.240
eventually made direct dialing of long-distant numbers more Universal and

00:04:50.919 --> 00:04:57.800
the use of PCS to hijack phone lines continues to this day we actually did a

00:04:55.960 --> 00:05:02.800
collaboration on our sister Channel L Tech tips with veritasium where they

00:05:00.120 --> 00:05:06.600
actually used ss7 to intercept calls to Linus's smartphone they did this by

00:05:04.680 --> 00:05:10.639
buying access to ss7 which is surprisingly easy to do for a few

00:05:08.080 --> 00:05:15.440
thousand bucks then using the access to steal a unique identifier code off the

00:05:12.919 --> 00:05:19.400
victim's SIM card after this is done an attacker can use that ID number to trick

00:05:17.600 --> 00:05:23.919
the network into thinking the victim's phone is roaming in a different country

00:05:22.280 --> 00:05:29.000
which results in the network routing calls and texts to a number registered

00:05:26.520 --> 00:05:33.080
with that country code that the attacker controls that was a really cool and

00:05:31.520 --> 00:05:37.880
frightening experiment so if you want to find out more go watch that video next
