The padlock in a browser is useful, but it does not mean what many people were taught years ago. It means the connection is encrypted. It does not prove the website is honest, official, or safe to buy from.
Does this affect you?
Use this for Chrome, Safari, Edge, Firefox, and other browsers on desktop or mobile whenever you are deciding whether to trust a website.
Understand the actual difference
HTTP and HTTPS describe how your browser communicates with the site.
- HTTP sends information in plain text. Passwords, searches, forms, and payment details entered on HTTP can be readable to someone positioned between you and the site.
- HTTPS encrypts that connection using TLS, so intercepted traffic appears scrambled instead of readable.
- The padlock only confirms that encryption is active. It does not verify the owner’s honesty or prove the page is not phishing.
- HTTPS certificates are easy and often free to get. Automated certificate services help the web become safer, but they also allow scam sites to display a padlock.
- Modern browsers warn about plain HTTP with Not Secure labels, especially near login or payment forms. That warning is real and worth respecting.
The short version: HTTPS protects data while it travels. It does not tell you whether the destination deserves your trust.
What the padlock does not tell you
Treat HTTPS as one baseline check, then verify the site itself.
- Read the domain carefully. A fake site can use an encrypted address with an extra letter, hyphen, brand word, or unfamiliar ending.
- Do not trust a link because the message calls it secure. A phishing email may use HTTPS and still lead to a fake login page.
- Look for broader trust signals such as a consistent official domain, working contact pages, clear policies, and no pressure to verify immediately.
- Type addresses yourself for banking, email, shopping, and other sensitive accounts rather than using links in emails or texts.
- Avoid entering sensitive data on any page marked Not Secure, even if the company name looks familiar.
More control
Old padlock advice is outdated
Years ago, certificates were harder to obtain and often involved more identity checks. Now encryption is widely available, which is good for privacy but weaker as a trust signal.
Many phishing sites use HTTPS
Security reports have repeatedly found that modern phishing pages often carry valid HTTPS certificates. A padlock can appear on a fake bank, delivery, or email-login page.
HTTP is still risky on public networks
The plain-text problem matters most on Wi-Fi you do not control, such as hotels, airports, and coffee shops. Avoid sensitive forms on HTTP anywhere, and be extra strict on public networks.
Sources
- CISA – Understanding Web Site Certificates (2025)
- Google Chrome Help – Why am I seeing a Not secure warning (2025)
- FTC Consumer Advice – How to Recognize and Avoid Phishing Scams (2025)
