Data protection

SNS subscription with insecure endpoint

Risk Level

Informational (4)

Platform(s)

Description

We have found an SNS subscription configured with HTTP protocol instead of HTTPS. Without HTTPS, a network-based attacker can eavesdrop on network traffic or manipulate it using an attack such as man-in-the-middle. We strongly recommend using only HTTPS-based subscriptions. For further details: https://docs.aws.amazon.com/sns/latest/dg/sns-security-best-practices.html
  • Recommended Mitigation

    Configure HTTPS endpoint for SNS subscription