Radio S-OFF is a different approach and since it's risky (I disassembled Radio image to see what can I do, I started by simple byte patching, and patched get CID routine but as people reported installing unsigned Radio bricks the phone, I didn't try that) and finding an exploit in radio image is...