Communication over HTTP

Requests over HTTP

Description

HTTP requests send sensitive data in plaintext, exposing it to interception and man-in-the-middle attacks. HTTP alone does not provide transport confidentiality, integrity, or peer authentication.

Potential impact

  • Information disclosure: Attackers may intercept sensitive data transmitted in plaintext.
  • Data tampering: Data may be modified in transit.
  • Authentication compromise: Stolen credentials may allow an attacker to impersonate a user.

Remediation

  • Use HTTPS and keep server-certificate verification enabled to protect transmitted data.
  • Use TLS 1.2 or later.
  • Configure the server and application to require HTTPS.

Examples

Before

python
# Unsafe HTTP requests
import requests

response = requests.get('http://example.com/api/data')

After

python
# Safe HTTPS requests
import requests

response = requests.get('https://example.com/api/data')

Explanation

  • Before: HTTP transmits sensitive data in plaintext and exposes it to man-in-the-middle attacks.
  • After: HTTPS and default server-certificate verification protect data in transit. Do not disable certificate verification with verify=False.

References