Longitudinal stability of Mini App privacy violations
Determine whether the privacy-policy violations observed in Telegram Mini Apps persist across application updates, accounting for the ability of developer-controlled infrastructure to change Mini App behavior without redistribution through the Telegram platform.
References
Several directions remain open. On the tooling side, we plan to extend the framework to iOS, which requires a different automation and interception stack, and to investigate root-free TLS interception in order to lower the barrier to independent replication. On the measurement side, a longitudinal campaign would establish whether the violations we document persist across app updates, a question made particularly relevant by the hot-update capability discussed in Section~\ref{sec:discussion}: apps served from developer-controlled infrastructure can change behavior without redistribution through the platform.