Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wasn't trying to be dramatic here: Without deleting an eSIM profile from a device, all implementations I know indeed disallow reinstalling the profile on another device. (The eSIM standard effectively enforces the singleton nature of an instantiated eSIM profile.) But of course most providers can re-issue eSIMs if required, just like they can mail a physical SIM replacement.

But in many cases, they either charge for it, require more or less involved bureaucratic acrobatics (including sending the QR code via physical mail as proof-of-address, because they've been burned badly by eSIM swapping), or both.

So the assumption that an eSIM activation (QR) code is more or less like a bearer token that you can keep in your password safe and use whenever required often does not hold true, especially when needed most (traveling internationally etc).

Fortunately, my provider is pretty good about it (I can instantly self-serve reissue an eSIM in their portal free of charge), but that seems to be the exception, and I also don't know how I feel about that, security-wise. (They don't offer 2FA, as far as I know.)



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: