Certificate pinning should be pretty easy to solve in this particular case: just get a proxy/VPN! The Faraday cage shenanigans are pretty cool though.
There are a few caveats (e.g. using a residential or mobile proxy would look less suspicious, in case Apple looks out for datacenter IP ranges), but I think it should work.
The VPS simply forwards traffic on port 443 to gspe1-ssl.ls.apple.com.
But I suppose, in this case Apple is deliberately using the wifi signals, not relying on IP so "just use VPN" doesn't work.