techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.7K
active users

#esim

10 posts8 participants0 posts today

Security Explorations reveals critical flaws in Kigen's GSMA-certified eSIMs, enabling profile theft, app injection, and user impersonation. The exploit leverages 2019 Java Card bugs, undermining trust in eUICC isolation and GSMA certification. Mitigation and disclosure coordination followed.

security-explorations.com/esim

security-explorations.comSecurity Explorations - eSIM security

Very interesting applied security research into the #GSMA #eSIM universe, specfically the use of the JavaCard VM with its questionable security architecture depending on an off-card bytecode verifier in the context of the eUICC which inherently contains eSIM profiles of different [competing] mobile operators, each of which can install arbitrary Java applets into the same eUICC. #GSM #3GPP #cellular #simcards
security-explorations.com/esim

security-explorations.comSecurity Explorations - eSIM security
Replied in thread

@brettcannon

I have no tips, but I have seen prices for Europe calling and data, so low it redoubles the diuble anger at the north American billionaires ripping us off.

80% of American and Canadian phone and data pricing is theft to make tax avoiding billionaires.

End billionairism.

#eu#phonePrice#eSim
Replied to LaF0rge

@LaF0rge and I guess what I want to workaround on a consumer eSIM may be interpreted as "malware" by GSMA, because it is not the intended purpose to have an #App or something remote-control and switch #eSIM profiles...

infosec.space/@kkarhan/1147997

Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)@LaF0rge@chaos.social yeah, that I did figure out with the whole #GSMA signing chain. - The few *"vendor independent"* options I've seen were mere *eSIM management* tools at the [LPA](https://github.com/EsimMoe/MiniLPA) / [LPAC](https://github.com/creamlike1024/EasyLPAC) level and subsequent #Apps from companies that sell #eSIMcards (aka. #eSIM in Triple-#SIM form factor) like #5ber, #EIOTCLUB, #9e and others... These do in fact work and I guess having something like [`lpa-gtk`](https://codeberg.org/lucaweiss/lpa-gtk) that can be remotely told to deploy/switch eSIMs is the closest to [what I'm looking for](https://infosec.space/@kkarhan/114795901857462897) that will be possible in the walled maze that GSMA forces everyone to walk through as they don't allow people to roll their own CI/CA and exercise control. - Granted as you hinted in your talk the reliance on having public internet access *kinda* defeats the purpose of a WWAN connectivity like 5G/4G/3G/2G so at best it allows for dynamically (with interruption) switch between eSIMs based off the current traffic pattern (i.e. from a narrowband flatrate or no base rate pay-as-you-go to a broadband flatrate or cheaper per-traffic plan). Fortunately I don't even need like *legacy services* like Voice/SMS and a phone number so it's easy to obtain eSIMs for that which neither expire nor incure standby fees.
Replied to LaF0rge

@LaF0rge yeah, that I did figure out with the whole #GSMA signing chain.

  • The few "vendor independent" options I've seen were mere eSIM management tools at the LPA / LPAC level and subsequent #Apps from companies that sell #eSIMcards (aka. #eSIM in Triple-#SIM form factor) like #5ber, #EIOTCLUB, #9e and others...

These do in fact work and I guess having something like lpa-gtk that can be remotely told to deploy/switch eSIMs is the closest to what I'm looking for that will be possible in the walled maze that GSMA forces everyone to walk through as they don't allow people to roll their own CI/CA and exercise control.

  • Granted as you hinted in your talk the reliance on having public internet access kinda defeats the purpose of a WWAN connectivity like 5G/4G/3G/2G so at best it allows for dynamically (with interruption) switch between eSIMs based off the current traffic pattern (i.e. from a narrowband flatrate or no base rate pay-as-you-go to a broadband flatrate or cheaper per-traffic plan).

Fortunately I don't even need like legacy services like Voice/SMS and a phone number so it's easy to obtain eSIMs for that which neither expire nor incure standby fees.

Professional LPA UI. Contribute to EsimMoe/MiniLPA development by creating an account on GitHub.
GitHubGitHub - EsimMoe/MiniLPA: Professional LPA UIProfessional LPA UI. Contribute to EsimMoe/MiniLPA development by creating an account on GitHub.

Does anyone know a good, #FLOSS-licensed implementation of the Android Managment API for non-#GAPPS / #degoogled devices that supports #eSIM provisioning?

Basically like #MiniLPA but #remote and on #Android or any #Linux.

  • I don't need like a complete eSIM issue infrastructure, but just something to i.e. push an eSIM profile (i.e. via ntfy to a device and make it install & activate / use it.

Not sure if #LucaWeiss or @LaF0rge have any ideas...
lucaweiss.eu/post/2024-06-24-e

Google for DevelopersAndroid Management API  |  Google for Developers

It takes a bit fiddling, but #MiniLPA is kinda awesome!

github.com/EsimMoe/MiniLPA

Professional LPA UI. Contribute to EsimMoe/MiniLPA development by creating an account on GitHub.
GitHubGitHub - EsimMoe/MiniLPA: Professional LPA UIProfessional LPA UI. Contribute to EsimMoe/MiniLPA development by creating an account on GitHub.

Paar relatief eenvoudige manieren waarop je Palestina en Palestijnen in Gaza materieel kunt steunen:

1. Doneer eSIMs: nog steeds de enige manier voor o.a  journalisten en hulpdiensten in Gaza om in contact te blijven: connecting-humanity.org/
Crowdfund: Crips for eSIM: chuffed.org/project/crips-for- IEDER BEDRAG WELKOM.

2. Voor de verschrikkelijk hoge kosten om te overleven: doneer aan GoFundMe's of via gazafunds.com/, en deel ze. IEDER BEDRAG WELKOM.

3. Doe mee met Boycott, Divestment en Sanction: bdsnederland.nl/ Gebruik de app Boycat.

4. Blijf praten over Palestina, op je werk, bij je vakbond en politieke partij. Deel info van decolonizepalestine.com/ Volg een workshop of koop een boek bij Workshops 4 Gaza: workshops4gaza.com/

5. Zoek je lokale pro-Palestina groep op en overleg of je ze ergens mee kunt steunen. Doe mee aan acties.

6. Steun Palestijnse initiatieven zoals the Sameer Project linktr.ee/thesameerproject die directe hulp op de grond geven.

#Palestina #FreePalestine #BoycottIsrael #Gaza #eSIM #PalestineSolidarity #EndApartheid #mensenrechten @israel @palestine #Action4Gaza

connecting-humanity.orgProviding internet access for people living in Gaza
Continued thread

3 complaints in the process, however:

1. Not all of the data transferred over.

Seems like partly #iCloud backup, partly Bluetooth comms, but some data is kept local to the phone only. Had to reauthenticate to a bunch of services, including the app which applies my #eSIM.

I'm going to have to go through the old phone with a fine-toothed comb to make sure all the important stuff transferred over. Not how I wanted to spend the next few evenings...

Paar relatief eenvoudige manieren waarop je Palestina en Palestijnen in Gaza materieel kunt steunen:

1. Doneer eSIMs: nog steeds de enige manier voor o.a  journalisten en hulpdiensten in Gaza om in contact te blijven: connecting-humanity.org/
Crowdfund: Crips for eSIM: chuffed.org/project/crips-for- IEDER BEDRAG WELKOM.

2. Voor de verschrikkelijk hoge kosten om te overleven: doneer aan GoFundMe's of via gazafunds.com/, en deel ze. IEDER BEDRAG WELKOM.

3. Doe mee met Boycott, Divestment en Sanction: bdsnederland.nl/ Gebruik de app Boycat.

4. Blijf praten over Palestina, op je werk, bij je vakbond en politieke partij. Deel info van decolonizepalestine.com/ Volg een workshop of koop een boek bij Workshops 4 Gaza: workshops4gaza.com/

5. Zoek je lokale pro-Palestina groep op en overleg of je ze ergens mee kunt steunen. Doe mee aan acties.

6. Steun Palestijnse initiatieven zoals the Sameer Project linktr.ee/thesameerproject die directe hulp op de grond geven.

#Palestina #FreePalestine #BoycottIsrael #Gaza #eSIM #PalestineSolidarity #EndApartheid #mensenrechten @israel @palestine #Action4Gaza

connecting-humanity.orgProviding internet access for people living in Gaza

𝗭𝗼 𝗮𝗰𝘁𝗶𝘃𝗲𝗲𝗿 𝗷𝗲 𝗱𝗲 4𝗚 𝗔𝗽𝗽𝗹𝗲 𝗪𝗮𝘁𝗰𝗵 𝗲𝗦𝗜𝗠 𝘃𝗼𝗼𝗿 𝗺𝗼𝗯𝗶𝗲𝗹𝗲 𝗱𝗮𝘁𝗮

Heb je een Apple Watch Cellular dan kun je hierop dankzij de ingebouwde eSIM een mobiel abonnement activeren. Hoe je de eSIM in de Apple Watch met 4G instelt zie je in deze tip.

iculture.nl/tips/apple-watch-c

iCulture4G instellen op de Apple Watch doe je zoZo blijf je altijd bereikbaar dankzij de Apple Watch eSIM.