HTTPS encrypts the connection between a visitor and your server. It says nothing about whether the business behind the site is legitimate, which is why Google removed the padlock icon from Chrome in September 2023 after finding that most users had misunderstood what it meant.
What it actually guarantees
Two things, both narrow and both worth having.
The connection is encrypted. Someone intercepting traffic on a shared network sees unreadable data rather than the contents of a form submission.
The traffic was not altered in transit. Content cannot be modified between server and browser without detection.
What it does not guarantee is anything about the operator. A certificate confirms control of the domain, not that the business is real, competent, or honest.
The padlock, and why it went
The padlock icon indicated an encrypted connection for roughly three decades, and a great many people read it as meaning the site was trustworthy.
Google's own research put a figure on this. In a study of 1,880 users, 89 percent misinterpreted what the padlock conveyed, with only around one in ten understanding it correctly and knowing it could be clicked for details.
That matters because phishing sites use HTTPS routinely. Certificates are free and issued automatically, so a fraudulent site can display exactly the same indicator as a bank. An icon widely read as "safe" was therefore actively misleading on precisely the sites where it mattered most.
Chrome replaced it with a neutral settings-style icon in version 117, released September 2023, on desktop and Android, and removed it entirely on iOS where it was not tappable. The lock remains inside the menu as an indicator of connection security rather than sitting in the address bar implying endorsement.
Plain HTTP continues to be marked "Not secure", which is the warning that still carries meaning.
Why it is now the baseline
- Browsers warn without it. A "Not secure" label beside your address on a page asking for a phone number is a conversion problem before it is anything else.
- It is a lightweight ranking signal. Confirmed years ago and modest, but there is no reason to be on the wrong side of it.
- Certificates are free. Automated issuance removed the cost argument entirely, and the overwhelming majority of page loads are now encrypted.
- Some browser features require it. Location access and various modern capabilities are restricted to secure contexts.
What businesses get wrong
Assuming the padlock verifies the business
The misconception this whole change was intended to address. Worth knowing personally as well as professionally, since it is the reason phishing works.
Paying for an expensive certificate
Certificates come in validation levels, and for an ordinary business site the free automated variety provides identical encryption. Higher-priced options add organisational verification that browsers no longer display prominently, so the visible benefit is close to nil.
Mixed content
A secure page loading an image or script over plain HTTP produces warnings or blocked resources. Common after a migration, and worth checking rather than assuming.
Not redirecting the insecure version
Installing a certificate without forcing all traffic to the secure address leaves both versions live, which is two addresses for every page and the problem described in URL structure decisions.
Letting it expire
An expired certificate produces a full-page browser warning that most visitors will not click past. Automated renewal is standard now, and worth confirming actually runs rather than assuming.
The practical summary
Have HTTPS, force everything to it, use a free automated certificate unless something specific requires otherwise, and confirm renewal is working.
Then stop treating it as a trust signal, because it never was one. Trust comes from the things in trust signals that actually work: verifiable details, real photographs, and specifics a sceptic could check.
Frequently asked questions
What does the padlock icon actually mean?
That the connection between the visitor and the server is encrypted and has not been altered in transit. It says nothing about whether the business is legitimate, since certificates confirm control of a domain rather than anything about the operator.
Why did Chrome remove the padlock icon?
Because research found most users misunderstood it. In a Google study of 1,880 users, 89 percent misinterpreted what the padlock conveyed, and since phishing sites use HTTPS routinely, an icon widely read as meaning safe was misleading where it mattered most.
Is HTTPS a ranking factor?
Yes, though a lightweight one confirmed years ago. The stronger practical arguments are that browsers label plain HTTP as not secure, which costs conversions, and that certain browser features are restricted to secure connections.
Do I need to pay for an SSL certificate?
Generally not. Free automated certificates provide identical encryption to paid ones for an ordinary business site. More expensive options add organisational verification that browsers no longer display prominently, so the visible benefit is minimal.
What is mixed content?
A secure page loading resources such as images or scripts over plain HTTP, which produces browser warnings or blocked resources. It commonly appears after a migration and is worth checking rather than assuming resolved.
What happens if my certificate expires?
Browsers display a full-page warning that most visitors will not click past, which effectively takes the site offline. Automated renewal is standard, but it is worth confirming the renewal actually runs rather than assuming it does.
West Coast Media Solutions Inc. builds websites for businesses across Canada and also operates a premium domain marketplace, which is a relevant interest to declare when reading anything below about buying domains. Registry policies change; verify current requirements before relying on them.
Thinking about a domain or a rebuild?
We build websites and have spent decades around domain names. Bring us the situation and we will tell you what it is worth and how to secure it.
Start a Conversation