Android now lets you transfer eSIMs between your phones
androidpolice.com
androidpolice.com
Caution: never use eSIM with your real phone number; always get a new phone number just for use with eSIM.
OTP does a way better job giving consumer absolutely control than the eSIM does for mobile providers. (Yeah, re-read that last sentence carefully).
Disclaimer: I do eUICC vulnerability analysis with eIM.
https://www.ericsson.com/en/blog/2023/12/simplifying-iot-inn...
eSIM has the advantage of allowing me to switch to cheaper services without paying $10 and waiting for a physical card to arrive. Is it's security crap? Well so is the security of my mobile provider's kiosk minimum-wager workers.
Reducing delays to near instantaneous is an argument, but having to pay $10 for a physical SIM sounds like a scam. Yet I've seen providers making people pay for eSIM as well so it seems they like to do this.
On my provider, physical SIM are free and available under 24h. eSIM are free as well and I haven't seen a single SIM on any local provider more expensive than 1€.
I still like the feature that I keep my number as long as I pay. With other 2FA I'm always one device failure from permanent lockout.
Namely that physical SIMs are an excellent security feature, provided carriers aren’t cavalier about managing them.
Nowadays US carriers put up a few more hurdles here and there after some highly publicized issues, but it’s still bonkers that I can ultimately just read off the ICCID of a card in my possession and get a number ported to it.
Most European carriers don’t allow you to bring your own SIM and will instead only link numbers to SIMs issued to the customer by themselves.
That in and of itself would make things safer, but, and this practice varies from carrier to carrier and country to country, often times they require in-person pickup with ID check or courier delivery with ID scan. Although there are also plenty that just send it to the address on file.
Coincidentally, SIM swapping is unheard of in a majority of European countries. ENISA claims about half of European telcos had zero(!) incidents in 2021. (That stat was easiest to find)
Honestly, with normal SIM cards this shouldn’t be possible, as you cannot program the keys into the card. There are some eSIM-on-SIM-cards that you could use if your phone isn’t eSIM capable. But again, would be nice to check.
You don't need to program the keys into the card, you program the card's identity/public key into the network.
What I guess you mean is, you buy an inactive SIM from Vodafone (which has Vodafone-known keys on it), and then you’re telling Vodafone to use that card.
By „bring your SIM“ I thought of something non-branded and was surprised.
Essentially that is what’s happening with eSIM, hence the need for the provisioning step that also makes transferring hard.
Yet again, having ported my phone number to Google Voice (GrandCentral back then), and never giving out whatever my current SIM's phone number is, pays off
Agreed.
My phone number lives at twilio and I couldn't tell you the physical phone number on my SIM card ... I have no idea what it is without looking it up.
In addition to the obvious benefits of never caring whether you lose your phone or being vulnerable to a SIM swap there are other "telco superpowers" that come along with this arrangement:
- I can text you, from my number, from the command line (curl API)
- I can lose my phone and still send and receive SMS (again, curl API)
- I can "sanitize" incoming text messages to ascii-256, block attachments, block or alert on silent SMS, etc.
- block lists for incoming voice and SMS
- CC incoming texts to a mailspool which allows me to browse my SMS history as if it were email (this one is particularly nice).
Finally, I cannot participate in a discussion of hosted/VOIP vs. physical SIM numbers without reminding readers that a "2FA Mule" solves the problems of providers not supporting VOIP numbers for 2A:
For SMS, Google Vooice both sends to and receives from email. I have a cronjob set up to `mail` a TextNow number that needs activity every 28 days to stay alive.
>- CC incoming texts to a mailspool which allows me to browse my SMS history as if it were email (this one is particularly nice).
Oh, I like this. I tend to delete most of my SMS-via-email, and the texts are always searchable in my Google Voice account, but can definitely see the appeal of always archiving all incoming texts with my mail so that I can use `mairix` for search.
>Finally, I cannot participate in a discussion of hosted/VOIP vs. physical SIM numbers without reminding readers that a "2FA Mule" solves the problems of providers not supporting VOIP numbers for 2A:
Nice. I do use my phone's SIM (now eSIM) number when (and only when) 2FA won't take Google Voice, but if I decide that is a meaningful security flaw, your approach would work.
Speaking of telco superpowers, I don't know if Twilio lets you do this but Google Voice has always supported voice calls by browser. The only time I make or answer a phone call on my phone is when I am away from my computer. When iOS 8 appeared, I'd enjoyed the equivalent of Continuity for years.
Source: GV user since Grand Central days.
Everything else (including paypal, fidelity, schwab, sofi, discover, capital one, to name a handful) work fine.
The Internet is more harsh than telco backend infrastructure.
Sorry, I still don't get it. Telco's backend is a mess. It has a profusion of processes and frontend systems for customer service teams to interface with user records, which creates all sort of loopholes. Any sufficiently motivated attacker can pull a SIM swap attack, as it happens frequently, and the weak link is always a variation of: a clueless agent somewhere trying to help a poor "customer" who dropped their phone in the toilet, and needs to urgently to recover the number.
Or are you suggesting that Google's GV backend is riskier than the carriers?
This seems to be impractical advice with the way devices are going. Look at iPhones.
Unfortunately, quite a few security practices are sometimes "impractical". If you go purely by practicality, all computers would always trust you and do as you request — what is that if not the most practical way of interacting with a computer?
You always need to decide where to place your personal trade-off, maximize in that direction, and be honest about it to yourself. If you don't care about security to this degree, buy an iPhone. If you don't care about their known shortcomings, use face ID and/or fingerprint sensors. Or buy a different phone.
> way devices are going. Look at iPhones.
Also, FTR, almost all US people have a distorted view of iPhone market share. It's only the US where they have about half the market. It's far less in the rest of the world. That said, they still have somewhat of a "technology leader" position where everyone else feels like they have to imitate it, so… meh.
i don't understand why people say "meh" about companies copying apple, _as if it is apple's fault_. it's samsung, google, huawei, etc. making those decisions. if apple has 20-30% marketshare in most of the world, but has stronger fanbase, makes more money, and pushes tech boundaries, of course other companies will want to follow.
I'm saying meh because people copying Apple include the dumb decisions Apple makes without applying their own brain. Which in case of this specific thread is removing physical SIM slots. This is both Apple's fault for making a questionable decision as well as other companies for copying it.
> if apple has 20-30% marketshare in most of the world
Apple's global market share in 2023 was just about 20%, carried by it being 39% in the US; as such it is in fact below 20% in most of the world.
How does Android protect against this? The carrier somehow disallowing it?
I've also had actual costs being charged when eSIM provisioning failed with "error -2" or whatever during travel and then carrier support refused to do anything about it (after taking my money for the card of course).
eSIM didn't make that policy, your carrier did.
I've needed to go from a full-size SIM to a mini to a micro to a nano over the years. Each time was a new physical SIM, each time was more of a "transfer" to the new SIM card.
The pretty different situation, the one izacus was complaining about, is when you take your active SIM out of one device and put it into a different device. eSIM broke this for them.
Provisioning an eSIM should be as simple as logging into your carrier's app or website and clicking a button or scanning a QR code. If it's any more complicated than that, your carrier sucks and you should start the porting process immediately. They're obviously customer-hostile and aren't deserving another month's subscription.
The reason I originally replied is because you said "it's not like eSIMs created or enabled that policy".
Even as a single policy, it affects a lot more situations now. eSIM enabled a big expansion of scope. And "different size SIM or if a SIM was broken" is significantly rarer than changing phones.
And additional SIMs are below 10 bucks.
A more general remarque so, I get it that sometimes companies monetize a tad too much. But then nobody is working for free, no service comes without cost for the provider and we all have to make money to pay our bills. Hence I do not get the "they are doing it onpy for money" attitude, especially on a site like HN with a considerable number of people making litteral FAANG money, money that comes exactly from these practices.
As someone who designed quite a few public systems like this, I can recognize one that's built with users in mind and one that's built with profiteering in mind.
There's no reason for eSIM to not be easily transferrable between devices like pSIMs are. There's no reason that the QR codes with provisioning tokens can't be reusable and revokable like pSIM ones. There's no reason that eSIM provisioning servers work on whitelist principle where they deny all phones the carrier doesn't profit from.
And yet now we have all that. And before (at least here in Europe, I'm aware that US citizens are very used and defensive about abusive business practices by their telecoms) we didn't.
Indeed there is none:
https://support.apple.com/en-us/HT212780
> Use eSIM Quick Transfer on iPhone
> Some carriers support SIM transfers from your previous iPhone to your new iPhone without needing to contact them. You can also convert your current physical SIM card to an eSIM.
The whole page is full of what eSIM can do, but it seems carriers are not too happy about that as many block things that should be outright possible.
There are tons of weird things that are impossible just because carriers, e.g I have a phone that can do eSIM or pSIM, I have a tablet that can do mobile, eSIM or pSIM. I have a nice data plan for the phone, and it is eligible to share it with a watch and/or a tablet. Such a hypothetical watch that I don't own would be eSIM, and be able to share the data plan but somehow the exact same case for the tablet can only be done via pSIM, neither can I convert its pSIM to an eSIM, which is allowed for the phone. It makes no sense.
AT&T already has a whitelist based on IMEI that works for pSIM too. https://redd.it/trfw5r
As always, be careful not to confuse the sample with the distribution. The commenter you are replying to is not necessarily one of those people. Also, their statement might be matter-of-fact, not a condemnation.
I didn't read it as "they're doing it only for money". That indeed is perfectly understandable. I read GP as saying, they're being customer-abusive asshats.
We all need to make money to pay our bills and such, however there's a subtle but important difference between selling some good/service/labor in exchange for money, and abusing the customer to extract money from them. eSIM, per GP, is designed very much for the latter case.
I don't even need to go to any location, I just need someone to send me a QR code.
It is extremely helpful and a huge time saver.
The only good use-case (for the user) is buying travel eSIMs.
I always use prepaid as i hate nasty contract surprises and also because its actually cheaper here with most carriers!
Actually I take that back, shady shops will sell you a SIM that can't be activated.
Things do change, so I did a quick internet search. Found plenty of websites with information on how to purchase and activate sim cards.
https://www.phonetravelwiz.com/buying-a-sim-card-in-germany-... https://abrokenbackpack.com/germany-sim-cards/
many others.
In that case customer identification is commonly done via the post office's Postident system (either at a physical post office, or online via video) or via some alternative video chat system, and those might not work for all passports from all countries worldwide.
Which countries? Of the few countries I traveled to, the cheapest esim (by using a esim comparison site) is cheaper than local sims for any reasonable amount of data (eg. 3 GB for a 2 week trip). The local sims sold at the airport might be "cheaper" on a per-GB basis, but they come with absurd amounts of data that you couldn't possibly use (eg. 30GB) so they are more expensive in actuality.
That means I assume they are paying roaming rates to the local providers.
But it all depends on the carrier now - I heard stories of carriers who won't send you the QR code, instead requiring you to drive to their store so they can show it to you in person "for security", defeating the whole purpose.
The old operator used the week to make me 3 increasing discount offers. Had I switched just for economic reasons I could have cancelled the operation on Saturday just before the scheduled transfer at Monday noon and saved a bit of money.
> The porting of numbers and their subsequent activation shall be carried out within the shortest possible time on the date explicitly agreed with the end-user. In any case, end-users who have concluded an agreement to port a number to a new provider shall have that number activated within one working day from the date agreed with the end-user.
My legalese is not good enough to understand what this means. The original text from the 2009 Telecoms Package[2] is worded slightly differently. Maybe member states failed to achieve the original intent and it was weakened to the current wording (as indeed, it takes longer than a day in many EU countries).
1: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... article 106, paragraph 5
2: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... article 30, paragraph 4
> Porting of numbers and their subsequent activation shall be carried out within the shortest possible time. In any case, subscribers who have concluded an agreement to port a number to a new undertaking shall have that number activated within one working day.
> In any event, loss of service during the process of porting shall not exceed one working day.
> From 1 July 2019 as a result of new rules from Ofcom, In the UK a customer can request a PAC without having to speak to their provider by texting PAC to 65075.
So it's more recent than I thought (the requirement, the 'donor-led' nature it mentions and ability to do it by text has definitely existed longer at least with willing networks) and UK thing postdating leaving the EU.
Once you have the new SIM the transfer is pretty quick.
The problem you are describing is therefore a regulatory one, not a technical one.
> Although carrier support is still limited,
Nope. eSIM is crap on android too.
Normally, the entire point of having a SIM in the first place is to have a secure storage element for the crypto keys authenticating the subscriber to the network... so similar to a TPM, it doesn't make sense for anyone to be able to extract the private key material, while it does make sense to be able to import new key material while at the same time only allowing authorized parties to do so - hence the entire dance with eSIM provisioning and multiple layers of cryptography involved.
But what's described in the article, at least to me, is that the source eSIM only creates some sort of token that a backend in the carrier then uses to provision a new set of keys for the destination device - so there will at least be some sort of record of such a change, and hopefully a way to prevent eSIM transfers... because otherwise this will be a pretty nasty attack vector, all you'd need to take over someone's phone number is to get their phone unlocked in your hands.
I hate the large-scale corporate gatekeeping combined with how insane the GSMA's security requirements and bullshit cert chains keep me from provisioning my own eSIMs for my own network compared to just buying a bunch of ISIMs from China to program in a reader.
I shouldn't need the carrier's, google's or apple's permission to use different phones.
The only exception is when the destination phone is carrier locked by a contract, but they have to unlock it for a nominal fee at the end (I think it was a few eur, or maybe last time they didn't charge me anything.).
Are you referring to the fact that no one buys contract free phones in the US?
All depends on if someone set this flag when creating your SIM and if you took their discount when buying their service.
Before esims you would have to go and get a physical SIM from somewhere. I've done it before. It's possible, but it was much more of a pain than esims.
The only issue with them I've found is that they're delivered by QR code via email, and the only way to install them on Android (that works) is scanning a QR code with your camera. I had do ask someone to take a photo of my phone so I could scan that photo. facepalm
This also has the benefit that the user cannot take it out or lose the SIM while traveling, or do SIM-swap with another device because their manager doesn't follow procedure of contacting IT when reusing spare phones between employees, creating all sorts of mismatches in the inventory between S/N and phone number, etc.
Wait. Why would you need, or want, an app for that? I'd automatically assume that any such app is a scam. These kinds of things are not what apps do, it's out of scope on restricted mobile OS.
He does say they're delivered via QR in the email, so the "application" is just a store frontend, it doesn't change his esim itself.
Apps like Airalo, etc, are legit.
IDK, I've always considered carrier apps to be the prototype example of garbage / scams, next to "value-add" software shipped by printer vendors. None of the services I pay my carriers for are, or were, ever enabled or improved by an app.
I'm locked down to my current phone because of eSIM. I have two eSIMs from different countries, both necessary for long-term use (e.g. I have bank accounts in both countries, and banks want local numbers). Replacing or upgrading phone would be a tricky endeavor, with temporary outage on one of my lines, as I will be able to move only one eSIM, but not the other until I physically travel to a different country.
Sure, it's a rare edge case, but still - super inconvenient.
... you mean, with Google/Apple's permission :)
It lists the cheapest e-SIMs for travelling to each country.
The one key thing that happened is that they sent me confirmations and steps to the email attached to my carrier. Besides that, the security features kick in, where I can make/receive calls, but data/SMS on that number is blocked for the next 24 hours (so, no 2FA and other credentials).
I was told by AirTel transferring my eSIM is not supported. I had to go to a store to get a new SIM (physical this time).
Hopefully the whole esim and namely esim transfer initiative would end phone as second factor.
And yes, I know that options for 2FA are limited in general. But phone is not the best one.
Which is usually how SMS 2FA are stolen, and no one is liable for the consequences.
Which means SMS 2FA is pretty low security. Convenient for most, but secure? Hardly.
> And yes, I know that options for 2FA are limited in general. But phone is not the best one.
Phone doesn't just mean SMS. E.g. bank apps in the EU use MFA with the bank's app directly which you have to unlock with biometrics or PIN, after unlocking your phone.
Phones are the best one.
Why?
Because (almost) everyone has one within reach.
Security enthusiasts and believers constantly fail to understand why straight passwords and to a lesser extent phone 2FA never go away: All their proposed alternatives and solutions are inconvenient.
Most people couldn't give a rotten rat's undead arse about security, but they will kill for convenience. Passwords and phone 2FA win and keep winning because they are convenient with good enough security.
Every part of the industry that matters has been bitten by using phone numbers as a 2FA mechanism. It's why they're actually disappearing and are being phased out in favor of apps, OTP tokens, and email codes, depending on the amount of influence technical people wield at a given org.
And all of them are some form of jank or inconvenience.
Look, most people (myself included) don't give a fucking fuck about security. Our time lost to the kabuki theater of security is worth more than the so-called "security" we gain, and that's assuming whatever is being secured is even worth securing.
A determined attacker will ignore all that and just undermine everything with social engineering against a useful customer support tech anyway.
Unless your solution is as simple as entering a password and hitting a button, which is the digital equivalent to taking out a key and unlocking your front door, it is not going to see widespread acceptance. Make your fucking security solutions convenient, not secure. kthxbai.
Even cars did away with keys because turning the ignition is an inconvenience compared to just pushing a button.
What password?
I mentioned the NHS app I use in a different sub-thread, so let's try my (not very good, would not recommend but they offered decent credit balance interest) current account. I tap the app on my phone, I get a whirl of nonsense, and then:
"Verify that it's you" and I touch the fingerprint sensor on my Pixel 6.
And that's it. No passwords, no PINs, no SMS messages, no separate authenticator device
This is much more secure than real human passwords (it'll be an elliptic curve signed message, so similar to HTTPS) and much more convenient, and short of convincing me to literally send you my phone and my finger you can't trick me into giving you access.
Consider, for example, banking apps: because 2FA via app being near-universal these days, even the web page doesn't let you use your bank account without installing the bank's app. And banks are, after MAFIAA, the biggest proponents of remote hardware attestation schemes. Thanks to that, we're reaching the point that phones that aren't locked down by Apple or Google are going to become useless. Mod/rooting scene already all but evaporated because of it - rooting your phone means fighting half the apps, including your bank, making the whole exercise not worth it.
Google and Apple could turn modern phones into convenient-to-use security keys/FIDO passkeys.
Not only that, they also both provide the same underlying technology to 3rd party apps, because the core trick in WebAuthn uses a cryptographic hash of a DNS name, so if we put say a UUID minted by your app store in where the DNS name goes we get the same functionality, (logically collisions can happen, but they're astronomically unlikely) but customised for each phone vendor & each app.
So e.g. I tap the icon for the NHS app on my Pixel 6, it starts up to where it would want me to do nonsense with passwords and so on but nope, hold my thumb against the screen, biometric match inside the phone, therefore this is my phone, it has a FIDO-style proof that this phone, which enrolled via the laborious process with passwords and SMS and whatever, is mine and it says this is me. Now I can order routine prescription re-fills, they go in a queue, my doctor says yeah, tialaramex doesn't need to re-check those blood levels until summer, prescription approved, done.
Big tech do it's best to trap users, let's say WA tied to a mobile phone number that after some time surrender and allow for a web access, still keeping the user trapped, but a bit less.
You can enslave as much as you can, a step at a time the barrier will drop. New others will be built and so on, why keeping up the fight?
(Everyone should stop using SMS for that anyway, btw.)
Best 2FA is a hardware device like YubiKey. I have a handful of YubiKeys, that I use in important places. Tying multiple YubiKeys to an account rather than just one is preferable IMO, because it lessens the risk of being locked out of your account when you lose a YubiKey or it breaks.
My setup for the next few years will be: Bitwarden to store passkeys, passwords and sensitive data and a Yubikey that I login to Bitwarden with.
OsmoDevCall - Exploring eUICCs and eSIMS using pySim, lpac and osmo-smdpp https://www.youtube.com/watch?v=9V1Vx35lZ5c
What eSIMs really are about: the industry fighting back against regulations restricting their anti-competitive SIM and carrier locking.
eSIMs are about is stripping owners of the control they have via pulling the physical SIM and putting it in another phone.
As a result, SIM locking does not have any benefit to the providers anymore and they stopped doing that.
That said, I have used eSIMs for years now and there is not much of a real benefit outside dual SIM in phones that only have one physical SIM slot (like iPhone). When first starting a subscription it's faster, because you don't have to wait until the SIM card comes through snail mail. But after that there is always the anxiety after switching to a new phone whether the eSIM transition goes well. With most providers you have to request the eSIM through their app on your new phone, you get a second factor code on your old phone (where the SIM is still active), then an eSIM is installed on the new phone, but only activated after you remove the eSIM from the old phone. Sometimes you get an error in the middle of the process and it's not clear whether the migration is complete or not.
Another issue is that if somehow the screen of your phone is destroyed, it's hard to move the eSIM to a replacement. While with a physical card you just pop it out and put it in your new phone.
I bought a bunch of cellular iPads off Amazon (“renewed”, aka refurbished) for my business. I tried out a few IoT cellular providers and the first one used regular SIM cards and they worked just fine. The second carrier (that I ultimately went with) used eSIM and while most my iPads joined up without issue I had 7 of them refuse to add the eSIM. While carriers aren’t allowed to lock iPads SIM they _are_ allowed to lock them to only work with their eSIM.
AT&T was the culprit here and you can find multiple mentions of this practice on their forums which appeared to be the only way to get help on this issue. Post a new topic, wait for customer support to come along and PM you, then ask for your iPads to be unlocked (EUICC).
AT&T Forum support ultimately told me “those iPads aren’t in our system, there is no lock on them”. I tried calling in (BTW, they won’t even talk to you unless you are a customer of theirs which, thankfully?, I was for my personal line) and spent hours on the phone with them only to be told the same thing. I want to be clear, I spent over 4 hours across multiple calls where I was told different things but ultimately told “there is nothing we can do”.
At this point I called Apple (Apple Business Manager) where I was able to talk to a real person within <1 min of dialing (normally I spent 10min in AT&T phone tree hell) and they confirmed “this is an EUICC/eSIM lock on the device by AT&T. ONLY AT&T can remove the lock”. I cannot rave enough about how easy it was to talk to ABM and how knowledgeable the person was, not to mention how they were easy to understand and immediately understood what I was asking. It was a stark difference from AT&T.
I called back into AT&T and just kept pushing until someone said they would do it and it’d be fixed in 24 hours. It was not. I had a couple more rounds with AT&T, each with 24-72 hours promises that it would be fixed. This dragged on for _weeks_.
Finally, as a hail mary before I attempted to return the troublesome iPads to Amazon (which was what AT&T support kept suggesting I do), I filed an FCC complaint and in less than 3 days AT&T reached out to me (no more automated systems) and released the lock on all my iPads. The same lock they swore didn’t exist, for iPads they swore were not “in their system”.
So yeah, there’s a case of anti-lock in being subverted with eSIM and the hell I had to go through to get it fixed.
If there is a specific law forbidding carriers to put any kind of block on a device using only physical SIM, but not if eSIM, I'll be interested to know that law. And if that's the case, wouldn't it be obvious that because eSIM is a relatively new thing, the law is just lagging behind, not that eSIM inherently a bad thing?
Technically it’s not a SIM lock (also called carrier lock) in the traditional sense, AT&T calls it the carrier visibility or carrier reveal program.
It’s a BS name because it doesn’t just hide other carriers from the carrier select screen, it also actively prevents eSIM activation via QR code etc. And if you need help from AT&T CS 9/10 have never heard of this term.
For all intents and purposes it’s basically just an eSIM specific SIM lock.
But you (and anyone reading this that runs into the same issue) can use the “carrier visibility/reveal” terminology to get the issue resolved faster in the future.
Yes, I forgot to mention that but I did know it at the time (I still have a doc with all those terms in it that I used when talking to the reps) and yes, almost no one knows what you are talking about. Even when I got someone to “put in a request” (which didn’t work) they sounded skeptical about what they were putting in a request for. It didn’t feel like they knew what I was talking about.
The only people that did use that term or understand it (other than the rep that contacted me after the FCC complaint) were the forum support but they told me the iPads weren’t in their system.
I'm more asking about cases where using an esim means the existing regulations don't apply, not instances of some shit company disobeying regulation until the regulator gets involved.
I feel like people with these comments don't realise that in many mobile markets carriers that do lockin don't do it via SIM cards, they do it via IMEI number locks on the phone. So even if you have a physical SIM card, you put it in another phone and it just doesn't work.
My carrier straight up doesn't support esim transfer as in moving the esim from one phone to an other, you have to renew / order a new one (as if you'd lost a physical sim basically).
It does not take too long once you find out you have to do that, and hunt down how to do it, but it's stressful, annoying, and dumb.
I’m not in the US and superficially, it seems like esim and physical sim don’t differ that much.
Unfortunately we have to suffer for a long time before regulation follows, if ever.
Then regulation follows and we get cookie banners sometimes.
The root cause of the cookie banner problem was implementing third-party cookies in the first place. Regulation is like violence; in both that if it doesn't work you just need more, and that if you needed to resort to it you've already fucked up.
We can't wind the clock back and give Netscape a slap, or stop the operators from introducing SIM-lock on handsets. The next best thing is to fix it now, and yeah, sometimes the wheels have to turn slowly.
What else do you propose we do? Refuse to use mobile data? (Actually, doesn't seem like the worst idea.)
In the meantime, don't buy esims. Nothing but drawbacks.
I have 4 eSIMs on my Pixel 7, 2 active, it's amazing.
Getting a new eSIM is also so easy, don't have to wait for a physical sim card to arrive.