A-CF-6

CloudFront Distribution not Compressing Responses

Risk:
Advisory

CloudFront Distributions that do not compress responses lead to slower applications and forfeit a positive ranking signal to search providers


Details

AWS CloudFront is a Content Delivery Network (CDN) that serves as the initial connection point for all your end users via the client applications they use, such as web browsers. Because CloudFront handles the direct communication with your users and their applications, CloudFront’s configuration usually affects all end user traffic and is a key part of ensuring efficient communication with users.

To guarantee that users receive optimized and fast-loading content, CloudFront should be configured to deliver compressed responses. Compression reduces data transfer size, allowing for quicker communication and enhancing overall application performance. This performance has compounding effects for dependency chains across assets such as modular javascript files or when users are on unreliable connections such as over mobile networks.

Additionally, third parties such as Google, use compressed responses as an indicator of a service’s reliability and performance where featuring compressed responses is treated as a positive ranking factor within Google Search. In addition to the indirect benefits of better application performance this signalling should provide a positive benefit to optimisation and ranking factors.

Remediation

SkySiege’s AWS Vulnerability Scan automatically detects this vulnerability across all AWS Regions with the report delivered the same day.

For every distribution ensure that the Compress objects automatically setting is set to Yes for all distributions. This can be found in the Behavior settings of your distribution.

Discover if you're vulnerable

SkySiege Cloud Security Assessments scan for this issue and provide same-day reports..
Available for individual projects or organisations.