Web tower · floor
HTTP vs HTTPS: what the padlock does not say
One letter separates them, and it stands for exactly one thing. The trouble is that people read it as standing for something larger — and the company that makes the most-used browser says so on its own help page.
That is Google’s own instruction, printed directly beneath the description of the secure
indicator — and it is the whole of the difference between the two words. HTTPS is about the
connection, not about the company at the other end of it. A page can be perfectly encrypted
and still belong to somebody who set it up this morning to collect card numbers. The padlock
says the envelope is sealed. It says nothing about who is receiving the letter.“Even when connected to a site securely, always be careful when you share
sensitive or personal information. Check the site name in the address bar to make sure
you’re on the site you want to visit.”
So the honest translation of the two is short. HTTP carries a page between a server and your browser in the open. HTTPS carries the same page inside an encrypted connection, so that, in Google’s words, what you send and receive “is private between you and the site”. The S is a promise about the pipe.
What it is not is a promise about the destination — and browsers have four different things to say on the subject, only one of which is about the site itself.
Google’s own wording. Only the last is a judgement about the site rather than about the connection.The four states Chrome distinguishes
Reading those four in order shows where the real judgement sits. The first three are all statements about the connection: private, not private, or something wrong with it. Only Dangerous is a statement about the site — and Google is explicit that it comes from Safe Browsing, a separate system that flags sites, rather than from anything the certificate proves.
Two verbs, and the second is the one usually left out. Without HTTPS the concern is not only
that somebody between you and the site could read the page — it is that they could alter
it: change a bank detail, add a download, rewrite a link. That is why browsers treat a
missing connection as a warning on ordinary pages and not only on payment ones, and why
Google’s remedy is addressed to the site rather than to you: “the site owner must secure the
site and your data with HTTPS.”“Someone may be able to view and change the information you send and get
through this site.”
That distinction matters more than it sounds. A certificate is not a character reference. It shows that the connection to a particular name is encrypted; it does not investigate who registered that name or what they intend to do. Which is exactly why Google’s advice on a secure page is not “relax” but “check the site name in the address bar” — the name is the part a certificate cannot vouch for on your behalf.
For a page without HTTPS, Google’s advice is plain: “We suggest you don’t enter any private or personal information on this page. If possible, don’t use the site.” Note what it does not say — it does not tell you to fix anything, because there is nothing on your side to fix.
The setting that asks first. Chrome has an option called Always use secure connections. Google describes what it does plainly: with it on, “if a site doesn’t support HTTPS, Chrome displays a ‘Connection is not secure’ warning”. So instead of quietly loading an unencrypted page, the browser stops and asks. For anybody who would rather be told than assume, that is the one switch on this page worth changing — and it changes the default from silence to a question.
There is one more thing worth knowing about what the icons do and do not tell you, and Google mentions it in passing. Selecting the symbol opens “a summary of the site’s privacy details, cookies and site data, permissions, history of visits, and information about the page”. The icon is a door as well as a status — and behind it is the list of what that site has been allowed to do on your machine, which is a more useful thing to read than the icon itself.
What this page will not tell you is that HTTPS makes a site trustworthy. That is the specific confusion it exists to correct, and repeating it in softer words would defeat the purpose. Encrypted and honest are two different properties, checked by two different mechanisms, and only one of them is reported by a padlock.
Nor will it tell you how to get a certificate for your own site — that belongs to the floors on hosting and domains, where the practical arrangements live.
The floors below take it three ways: what the connection protects, what it does not, and the neighbouring things a browser reports about a page.
Where to start
Three ways in. If the question is “is this site safe”, take the second.
- “What does the S actually add?”
- One thing, precisely — what the s adds
- “Is this site safe because it has a padlock?”
- No — read what it does not say
- “The browser says not secure.”
- That is the site owner’s to fix — the four states
What the S adds
An encrypted connection, so that what you send and receive is private between you and the site. That is the whole of the difference, and it is a real one.
What it does not say
Nothing about who owns the site or what they intend. Google’s own advice on a secure page is to check the name in the address bar, which is the part no certificate covers.
The four states
Secure, not private, not secure, dangerous. Three describe the connection; only the last describes the site, and it comes from a different system.
What this tower will not do
It will not tell you a padlock means a site is trustworthy. Google prints a warning to keep checking the address directly beneath its own description of the secure indicator.
It will not treat the four browser states as four grades of safety. Three of them describe the connection and one describes the site, and they are not on the same scale.
And it will not tell you to work around a “not secure” warning. Google says the site owner is the one who has to fix it, and that there is nothing to enter on such a page in the meantime. What holds instead is simple: the descriptions of the secure, not private, not secure and dangerous states, the instruction to check the site name in the address bar even on a secure connection, the note that someone may view and change information sent over an unsecured connection, the statement that the site owner must secure the site with HTTPS, the advice not to enter personal information on an unsecured page, the Always use secure connections setting and its warning, and the summary of privacy details available behind the icon are quoted from Google’s Chrome help documentation, listed below.
Where this page got its facts
- Google, Check if a site’s connection is secure — Chrome Help (that the symbols beside the web address indicate whether Chrome has or has not established a secure and private connection with a site; that on a secure connection the information sent or received through the site is private between the user and the site, together with the instruction that even when connected securely one should always be careful when sharing sensitive or personal information and should check the site name in the address bar to make sure it is the intended site; that a site without a private connection may allow someone to view and change the information sent and received, that the site owner must secure the site and the user’s data with HTTPS, and that private or personal information should not be entered on such a page and the site avoided if possible; that a “not secure” state means something is wrong with the privacy of the site’s connection and that someone might be able to find the information sent or received; that a full-page red warning means the site has been flagged as unsafe by Safe Browsing, can misuse or abuse any information it receives and could attempt to install harmful software, and should not be used; that selecting the icon shows a summary of the site’s privacy details, cookies and site data, permissions, history of visits and information about the page; and that with the Always use secure connections setting turned on, Chrome displays a “Connection is not secure” warning when a site does not support HTTPS) — support.google.com, read 22 August 2026.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Written on 22 August 2026.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.