Live data from Hacker News

Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

arstechnica.com

91–100 of 199 posts

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#91

Why is this a positive story? Downsides: -it is more cumbersome to replace phones, as you have to move identities from phone to phone and get approvals by carriers and device makers instead of just replacing the physical SIM -you can't just hand over your phone to someone else, you have to unroll yourself and enroll the other person -you don't have anonymity and privacy since is no longer possible to use a prepaid ph…

> it is more cumbersome to replace phones, as you have to move identities from phone to phone and get approvals by carriers and device makers instead of just replacing the physical SIM

That really depends on the carrier. In my case, setting up a new iPhone to replace an old one means saying yes in the prompt displayed by the phone. Nothing else. This is more convenient than having to search for the SIM removal tool.

> -you can't just hand over your phone to someone else, you have to unroll yourself and enroll the other person

For me this is a big feature because I would never hand my phone to somebody else, but an attacker is very likely to remove the SIM card and put it into their phone. Now suddenly many 2FA accounts are protected by a 4 digit PIN rather than my 20 digit phone passphrase.

> -you don't have anonymity and privacy since is no longer possible to use a prepaid physical SIM

It works exactly the same way as it did with physical SIM cards only the physical card is replaced by a QR code displayed on a screen or a printed paper. If the carrier sells anonymous prepaid SIM cards, nothing prevents them from selling anonymous prepaid QR codes.

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#92
post #74

Earlier quoted context omitted.

Dual-SIM phones were the hot shit for years when phones were beginning to take off. I remember some weird adapters that cycled through SIMs when the phone was restarted and all kinds of other hacks.

You don't even need Dual-SIM phones, contemporary SIM can contain various numbers/administrations. Both with and without hackery involved. It's just that the carriers don't want it / block it. This is also why many of them outright refuse to sell phones with dual SIM capability.

> This is also why many of them outright refuse to sell phones with dual SIM capability.

At least here in the EU, carriers don't follow typical US customs any more... a series of court verdicts following the 2005 commerce directive has all but eliminated SIM locking and other hostile practices by carriers, the worst you (unfortunately) still get is bloatware.

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#93

Why is this a positive story? Downsides: -it is more cumbersome to replace phones, as you have to move identities from phone to phone and get approvals by carriers and device makers instead of just replacing the physical SIM -you can't just hand over your phone to someone else, you have to unroll yourself and enroll the other person -you don't have anonymity and privacy since is no longer possible to use a prepaid ph…

Coming from the original point of view that "we don't need these physical cards anymore" .. You actually make some really solid points. Specifically the ability to resell your phone conveniently.

Imagine having to agree on a sale and then waiting for the changeover process to complete. Which knowing certain phone carriers would take at least 24 hours.

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#94
post #30

Earlier quoted context omitted.

Security. SIMs are smartcards - separate systems storing cryptographic material and performing trusted operations. A TPM that can be plugged and unplugged, basically, using the same standards as a chip-and-pin credit card. Equivalent keystores haven't been available built in to cell phones until the last few years.

TrustZone and Secure Element have been available for quite some time now. I think this problem is more because carriers/users don't want to give up control to software companies than it's about lacking hardware.

TrustZone is iffy security-wise, and built-in SEs have only been available for iPhones and the highest-end quarter or so of Android phones until recently.

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#95
post #84

Earlier quoted context omitted.

Yeah AFAICT this article is just: Qualcomm is now a certified producer of eSIMs. They put them in the SoC. Everything else including the term "iSIM" just seems to be marketing cruft? Perhaps I'm missing some detail but it seems the only people who would have any reason to care about this would be Qualcomm's customers in the mobile OEM space.

Because it's in software, they can legally disable your phone and force you to buy a new phone every 3 year citing "security patches no longer being issued". Bye bye aftermarket firmware second life !

What do you think would stop them from doing this to a phone using a physical SIM card? I don’t see how an eSIM makes a difference in this scenario.

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#96
post #30

Earlier quoted context omitted.

Security. SIMs are smartcards - separate systems storing cryptographic material and performing trusted operations. A TPM that can be plugged and unplugged, basically, using the same standards as a chip-and-pin credit card. Equivalent keystores haven't been available built in to cell phones until the last few years.

TrustZone and Secure Element have been available for quite some time now. I think this problem is more because carriers/users don't want to give up control to software companies than it's about lacking hardware.

What apple calls Secure Element is a separate chip that essentially is an eSIM with NFC interface (or in other words, smart card MCU with larger memory and more IO). Apple's implementation of what TrustZone is supposed to solve is called Secure Enclave and also involves separate CPU core (inside the application SoC) that is isolated from the application cores by how the hierarchy of various buses on the chip is structured.

I assume that there are two reasons why it is done this way instead of software/weird-CPU-state solutions (like TrustZone): this construction is easier to reason about and at least in the Secure Element case easier to certify to the requirements of card issuers (as it is essentially standard off-the-shelf secure MCU).

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#97

Earlier quoted context omitted.

I was really thinking of being able to grab an eSIM directly for a local network, rather than one of the "global eSIM providers". You'd just grab your eSIM over WiFi when you land rather than seeking out a physical SIM from an airport vendor. Obviously it's not the reality that these are easily available in all destinations, yet, but should become more so over time.

There's frankly no reason for a local network to make it easy for foreigners to sign up when they can instead get paid 10x as much in roaming fees if the foreigner stays on their home network instead.

Sure there is: competition. Why let your competitor network grab those 10x roaming fees when you can grab the 1x yourself? Last time I was in Thailand, vendors at the airport were practically falling over themselves to sell you their SIM card on their network!

Besides, I doubt roaming fees are all that lucrative considering all the "free global roaming" plans there are now days. Those networks that charge crazy per-MB roaming rates are, presumably, keeping most of it for themselves.

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#98
post #84

Earlier quoted context omitted.

Because it's in software, they can legally disable your phone and force you to buy a new phone every 3 year citing "security patches no longer being issued". Bye bye aftermarket firmware second life !

They could be doing this already if they wanted to. I agree they shouldn't have this ability in the first place, but this doesn't change anything.

They can't do that with physical SIMs, because at least in the EU, there are regulations against that (to regulate stuff like phones and SIMs locked to each other)

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#99

This seems like an inevitability; since eSIMs are already here, and manufacturers are going to be thrilled to have fewer moving parts. But it’s disappointing all round. I absolutely love how easy it is for me to buy a new phone, swap in my old SIM and I’m instantly using my old number. As painful as transferring everything else is with new phones, at least I easily keep the same number. With this (and I’d guess with…

With eSIM when I buy a new phone I just open my provider’s app on my old phone and request a new SIM, then scan a QR code on the new phone and bam my new phone is setup using the same phone number. You can have multiple eSIMs on the device and activate them when you need… for example travel SIM, or a SIM for your home country, etc. It’s way more convenient than physical SIM cards.

You can have multiple physical SIMs with any reasonable phone as well. It's only the handful of US flagship phones that removed that support (just as they removed headphone jacks or microSD slots)

Re: Qualcomm wants to replace eSIMs with iSIMs, has the first certified SoC

#100

Earlier quoted context omitted.

There's frankly no reason for a local network to make it easy for foreigners to sign up when they can instead get paid 10x as much in roaming fees if the foreigner stays on their home network instead.

Sure there is: competition. Why let your competitor network grab those 10x roaming fees when you can grab the 1x yourself? Last time I was in Thailand, vendors at the airport were practically falling over themselves to sell you their SIM card on their network! Besides, I doubt roaming fees are all that lucrative considering all the "free global roaming" plans there are now days. Those networks that charge crazy per-M…

Free global roaming is paid by the home carrier - it doesn't necessarily make it free at the visited carrier.
Post reply on HN