People constantly misuse that quote to claim that "obscurity" should never be used. This is false; denying your opponent information is a critical component of a well-designed security process.
It should not be the only mechanism employed.
(I have no clue what, if any, other measures Pakistan employed.)
You are absolutely correct. Having worked in the field I can tell you that Security Research into iPhones is a lot harder than Android.
You have the full source of major important components of Android (like the OS Kernel), and you have very little of that for iOS. They've both got great, constantly advancing security models, but the iPhone's extra layer of security will continue to give it the edge (in my opinion at least).
As an end user I use obscurity as my means to deny information - for instance at ATM when asked for a pin I would purposely touch a few more keys to break the sequence on the ATM machine.
It should not be the only mechanism employed.
(I have no clue what, if any, other measures Pakistan employed.)