2026-habib-empirical-study-backend
findings extracted from this paper
-
Device-centric security analyses systematically underestimate user data exposure because backend infrastructure placement and jurisdictional context — not just on-device behavior — determine which actors can access sensitive data; a five-service geolocation ensemble (MaxMind, IPinfo, ip-api, DBIP, BGPView/RIPE) with CDN-aware attribution and WHOIS/BGP mapping was required to accurately characterize server-side risk.
-
Three of the four active first-party sensitive-data endpoints in Pakistani government and telecom apps rely on domestic Pakistani infrastructure, identified via ASN and registry-level signals pointing to local administrative entities — placing identity credentials, location, and communication metadata within reach of Pakistani government administrative access.
-
Across approximately 172 observed domains in 7 Pakistani government and telecom apps, only 4 active first-party endpoints handle highly sensitive data — including identity credentials, location information, and communication metadata — revealing extreme concentration of sensitive data flows into a small number of reachable endpoints.
-
App store listings and privacy documentation for Pakistani government and telecom apps show limited disclosure of data retention and deletion policies, even for apps handling identity credentials, location data, and communication metadata — creating an accountability gap between what users can verify and what data the backend infrastructure actually retains.
-
One of the four high-sensitivity first-party endpoints is served through U.S.-based CDN infrastructure despite being organizationally associated with Pakistan, demonstrating that backend jurisdictional placement is not determined by organizational affiliation alone and can introduce geographic ambiguity in data governance.