Cleartext Transmission

Cleartext transmission in C#

Description

Sending application traffic to an http:// endpoint allows a network attacker to intercept or modify requests and responses. Calls to external services in production should use HTTPS.

Potential impact

  • Exposure or modification of authentication tokens, session identifiers, personal information, and business data.

Remediation

Use https:// URLs for external API and service calls. Apart from explicit local development endpoints such as localhost or loopback addresses, do not leave plaintext HTTP endpoints in production code.

Examples

Before

csharp
await httpClient.GetAsync("http://api.example.com/status");

After

csharp
await httpClient.GetAsync("https://api.example.com/status");

Explanation:

  • Before: Plaintext HTTP can expose sensitive application traffic to network attackers.
  • After: Use HTTPS for external application traffic and restrict HTTP to explicitly designated local development endpoints.

References