Working on a decent writeup as we speak, You are indeed right.
Edit:
http://el.che.moe/Writeup_VoiceAttack.html
Edit: Added two programs that Encrypt and Decrypt the server response / What you want to spoof to register it.
Edit: had to remove it because my hot has received a lot of copyright strikes lately.