I mean its just for notification to my app so its not something critical
I mean its just for notification to my app so its not something critical
If your threat model is such that you'd rather not have the server know what's sent to and from the client, it's not enough to just encrypt the data in flight, which is what HTTPS does. With encrypted chat, we typically want what we refer to as end-to-end encryption, where the server can't see the content of messages sent between users.
I want to prevent vector attack such MiTM if TLS is somehow hacked
There are things you can do to make it more difficult to hack your TLS connection though, for example you could use key pinning to make sure that your app will only accept a server with the certificate you expect. This would protect against an IT admin installing root certs on their users' devices, or against certificate authorities issuing fake certificates for your domain.
but for things like IoT running websocket connection for long time maybe I need that
When your server facilitates a communication between two clients and just acts as the infrastructure E2EE can become relevant. If the clients want to be able to exchange information withouth the server being able to snoop in on what is being sent, then you'd want to use E2EE. With that the server won't be able to read what is being sent.
- then notification service is probably something I want to E2EE then, but Idk about performance hit cost would be
If so, then you really don't need any extra encryption.
If not, then it depends on who's using your chat, how they use it, and for what purpose. Are the users of the chat room a small group with occasional users joining or leaving, or are many users expected to join and leave at any given moment?
That being said, encrypting the notifications won't bring any real benefits. A bad actor would simply focus on trying to compromise your server.
If you do decide that full e2ee would benefit your users, then look for someone who can help you implement it.
Implementing real e2ee for a 2 party chat is hard for someone without experience.
Implementing e2ee for a group chat is hard even for someone with experience.
(Though I still think that "how can I protect against TLS being broken?" is the wrong question and you should instead ask "how can I ensure that TLS doesn't break?".)