FINDING · DEPLOYMENT
Across approximately 172 observed domains in 7 Pakistani government and telecom apps, only 4 active first-party endpoints handle highly sensitive data — including identity credentials, location information, and communication metadata — revealing extreme concentration of sensitive data flows into a small number of reachable endpoints.
From 2026-habib-empirical-study-backend — An Empirical Study of Backend Infrastructure in Leading Pakistani Mobile Apps · Abstract · 2026 · FOCI 2026
Implications
- Route all traffic through a VPN or proxy tunnel rather than inspecting app-layer destination counts alone; the small number of sensitive endpoints means a single unprotected connection to a government app can expose the most sensitive user data.
- Prioritize coverage of government/telecom app traffic (not just browser traffic) in circumvention tooling, since sensitive credential and location data concentrates in a handful of identifiable first-party endpoints outside the browser.
Tags
Extracted by claude-sonnet-4-6 — review before relying.