Data protection

SNS subscription with insecure endpoint

Platform(s)
Compliance Frameworks

Description

We have found an SNS subscription configured with HTTP protocol instead of HTTPS. Without HTTPS, a network-based attacker can eavesdrop on network traffic or manipulate it using an attack such as man-in-the-middle. We strongly recommend using only HTTPS-based subscriptions. For further details: https://docs.aws.amazon.com/sns/latest/dg/sns-security-best-practices.html