5 ms·
I think that the risk is more about stealing the number more than reprogramming it. If I can move my eSIM to a new phone, so can an attacker.
by feupan 5y ago
I think that the risk is more about stealing the number more than reprogramming it. If I can move my eSIM to a new phone, so can an attacker.
- saltminer 5y agoThis is already a problem with regular SIM cards and people social-engineering customer support reps into getting their SIMs provisioned with other people's numbers. Carrier incompetence will exist regardless of if the SIM is physical or virtual.
- mschuster91 5y ago> If I can move my eSIM to a new phone, so can an attacker. No, they can't - there is (at least for modern SIM cards and eSIM modules, see [1]) no way short of decapping the chip to extract the secret keys once they are on the chip, and even de-capping is something that the chip industry has gotten pretty good on defending against. An attacker would have to request a new eSIM profile (aka, new keys) from your provider to hijack your number, which is an entirely different threat model. [1]: https://www.kaspersky.com/blog/sim-card-history-clone-wars/11091/ https://www.kaspersky.com/blog/sim-card-history-clone-wars/1...
- feupan 5y agoI don’t know how you can say they can’t. The eSIM is just a number. An attacker can install it exactly the same way I did: I copy-pasted some numbers from an eSIM provider’s app. I’m not talking about getting the number from the phone, but directly from the operator.