Data protection

SNS subscription with insecure endpoint

Risk Level

Informational (4)

Compliance Frameworks


We have found an SNS subscription configured with HTTP protocol instead of HTTPS. Without HTTPS, a network-based attacker can eavesdrop on network traffic or manipulate it using an attack such as man-in-the-middle. We strongly recommend using only HTTPS-based subscriptions. For further details:
  • Recommended Mitigation

    Configure HTTPS endpoint for SNS subscription