Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@LaF0rge" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>LaF0rge</span></a></span> yeah, that I did figure out with the whole <a href="https://infosec.space/tags/GSMA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GSMA</span></a> signing chain.</p><ul><li>The few <em>"vendor independent"</em> options I've seen were mere <em>eSIM management</em> tools at the <a href="https://github.com/EsimMoe/MiniLPA" rel="nofollow noopener" target="_blank">LPA</a> / <a href="https://github.com/creamlike1024/EasyLPAC" rel="nofollow noopener" target="_blank">LPAC</a> level and subsequent <a href="https://infosec.space/tags/Apps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Apps</span></a> from companies that sell <a href="https://infosec.space/tags/eSIMcards" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIMcards</span></a> (aka. <a href="https://infosec.space/tags/eSIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIM</span></a> in Triple-<a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a> form factor) like <a href="https://infosec.space/tags/5ber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>5ber</span></a>, <a href="https://infosec.space/tags/EIOTCLUB" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EIOTCLUB</span></a>, <a href="https://infosec.space/tags/9e" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>9e</span></a> and others...</li></ul><p>These do in fact work and I guess having something like <a href="https://codeberg.org/lucaweiss/lpa-gtk" rel="nofollow noopener" target="_blank"><code>lpa-gtk</code></a> that can be remotely told to deploy/switch eSIMs is the closest to <a href="https://infosec.space/@kkarhan/114795901857462897" rel="nofollow noopener" target="_blank">what I'm looking for</a> that will be possible in the walled maze that GSMA forces everyone to walk through as they don't allow people to roll their own CI/CA and exercise control.</p><ul><li>Granted as you hinted in your talk the reliance on having public internet access <em>kinda</em> defeats the purpose of a WWAN connectivity like 5G/4G/3G/2G so at best it allows for dynamically (with interruption) switch between eSIMs based off the current traffic pattern (i.e. from a narrowband flatrate or no base rate pay-as-you-go to a broadband flatrate or cheaper per-traffic plan).</li></ul><p>Fortunately I don't even need like <em>legacy services</em> like Voice/SMS and a phone number so it's easy to obtain eSIMs for that which neither expire nor incure standby fees.</p>