while still havent tried the service, still posted negative review for now over there:
https://monero.forum/reviews
above poster did a lenghty thread reviewing all the esim providers over there:
https://monero.forum/thread/tested-no-kyc-esim-providers-actually-take-monero-notes-what-works
and yet had their question unanswered regarding USPs (Unique Selling Points)
OP being dismissive to my post with a: "Why would you need to trust an eSIM service?"
just asked LLM what would be the concerns regarding mobile data providers and what would be mitigated and what would not be mitigated by using grapheneOS/VPN, output from the prompt was:
1. Cell Tower Geolocation — NOT mitigated. The modem/baseband communicates with towers at the firmware level. GrapheneOS can't spoof what the SIM reports (IMSI, TMSI) or which tower you're handed off to. The carrier tracks physical location regardless of OS.
2. Traffic Metadata — NOT mitigated at the provider level. The carrier still sees encrypted packets to your Tor/VPN endpoint, their size, timing, and volume. They can detect Tor usage (known node IPs) and perform traffic analysis on packet timing patterns (website fingerprinting). The destinations are hidden, but the metadata is not.
3. Monero Timing Side-Channel — NOT mitigated. GrapheneOS doesn't alter when you pay or activate. Payment timestamp + network activation time + tower location at that moment is still a correlatable triplet.
4. Device Fingerprinting at Provisioning — PARTIALLY mitigated. Vanadium (GrapheneOS browser) has anti-fingerprinting patches (restricted WebGL, reduced canvas entropy, no PDF viewer). But enough entropy remains: screen resolution, timezone, installed font set, browser version. Mitigation depends on the browser you use, not the OS itself.
5. Wholesale Carrier Exposure — NOT mitigated. GrapheneOS has no control over the upstream carrier (BICS/Tata/Truphone etc.) that actually peers your traffic. They see everything the MVNO sees.
6. Honeypot/Seizure Risk — NOT mitigated. If the provider is adversary-run or gets seized, the data and infrastructure are out of your control. No OS-level protection applies.
7. VPN Illusion — PARTIALLY mitigated. GrapheneOS's always-on VPN + kill switch prevents cleartext leaks if the VPN drops. Orbot/Tor integration works well. But the carrier still sees: Tor entry node IPs (known), traffic volume/shape, and tower location — so the "illusion" is reduced but not eliminated.
Summary: GrapheneOS helps with device-level leaks (app permissions, network kill switch, browser fingerprinting), but does nothing against the network-level visibility the carrier inherently has (location, traffic metadata, timing correlation). The unmitigated risks are structural, not OS-dependent.
did a follow up prompt:
isnt location somewhat approximate tho? is it through triangulation or something else? how precise is it compared to like GPS data, does the carrier can access that data too?
output was:
Triangulation vs. GPS:
Cell triangulation (OTDOA/UTDOA/RTT): 50–300m typical on 4G; 5G NR positioning can hit <10m in dense urban (rivals GPS). Rural areas are worse (1–5 km). The modem reports timing measurements to the network at the firmware level — GrapheneOS can't touch this.
Yes, the carrier can access GPS-level precision — and this is the bigger point. The modem has its own GPS receiver and responds to LTE Positioning Protocol (LPP) requests from the network independently of Android. Even with device location services disabled, the network can request GNSS measurements via SUPL (Secure User Plane Location) and the modem will respond. This is part of the 3GPP standard, baked into baseband firmware.
So the real situation is worse than "the carrier has approximate triangulation." The carrier can effectively get GPS coordinates from your modem on demand, regardless of what the OS does, and there's no way for GrapheneOS to block it because it happens below the application processor level.
interestingly enough, 2G towers been discontinued in many countries already, more still planning shutting those down coming forward, for USA AT&T 2G ded since 2017, Verizon since 2020, T-Mobile since feb 2025
which apparently, 2G would be safer against the carrier itself, way worse regarding any attackers within radio range, so if the threat model is the carrier because corporate slop, that sucks lol, options are nice depending on threat models lol, o7
edit:
well i guess XMRSIM might not even be a phone carrier thing but literally just a reseller of esim giftcards type thing?
they did a reply on some other thread today tho, worthy of some pothead that has no clue of what even is what, the unanswered question was from a different user (the post above), not from myself and was literally a simple one liner, not even a long post but they called it "LLM powered critique", like, nah, one liner simple question from a different user
if that's what's expected from their customer support then yea, ill pass on that and stand by the negative review i left