Actually, they (he) did. It is done by pointing variables to ROM instead of RAM, and sending them back to the PC (simply put). http://www.ticalc.org/pub/text/calcinfo/85hack.txt > They did not, however, get access to the ROM itself until AFTER they > attained the ability to execute the assembly code (through the custom > menu... though there are a few other holes...)