Web tower · floor

HTTP vs HTTPS: what the padlock does not say

One letter separates them, and it stands for exactly one thing. The trouble is that people read it as standing for something larger — and the company that makes the most-used browser says so on its own help page.

Even when connected to a site securely, always be careful when you share sensitive or personal information. Check the site name in the address bar to make sure you’re on the site you want to visit.”

That is Google’s own instruction, printed directly beneath the description of the secure indicator — and it is the whole of the difference between the two words. HTTPS is about the connection, not about the company at the other end of it. A page can be perfectly encrypted and still belong to somebody who set it up this morning to collect card numbers. The padlock says the envelope is sealed. It says nothing about who is receiving the letter.

So the honest translation of the two is short. HTTP carries a page between a server and your browser in the open. HTTPS carries the same page inside an encrypted connection, so that, in Google’s words, what you send and receive “is private between you and the site”. The S is a promise about the pipe.

What it is not is a promise about the destination — and browsers have four different things to say on the subject, only one of which is about the site itself.

The four states Chrome distinguishes

Google’s own wording. Only the last is a judgement about the site rather than about the connection.

Secure
Information you send or get through the site is private between you and the site.
Not private
“The site doesn’t use a private connection. Someone may be able to view and change the information you send and get through this site.” Note “and change” — the risk is not only being read.
Not secure
“Proceed with caution. Something is wrong with the privacy of this site’s connection. Someone might be able to find the information you send or get through this site.”
Dangerous
Do not use this site.” A full-page red warning means the site “has been flagged as unsafe by Safe Browsing” — it “can misuse or abuse any information it receives, and could potentially attempt to install harmful software on your computer”. This one is about the site, and the judgement comes from a separate system.

Reading those four in order shows where the real judgement sits. The first three are all statements about the connection: private, not private, or something wrong with it. Only Dangerous is a statement about the site — and Google is explicit that it comes from Safe Browsing, a separate system that flags sites, rather than from anything the certificate proves.

“Someone may be able to view and change the information you send and get through this site.”

Two verbs, and the second is the one usually left out. Without HTTPS the concern is not only that somebody between you and the site could read the page — it is that they could alter it: change a bank detail, add a download, rewrite a link. That is why browsers treat a missing connection as a warning on ordinary pages and not only on payment ones, and why Google’s remedy is addressed to the site rather than to you: “the site owner must secure the site and your data with HTTPS.”

That distinction matters more than it sounds. A certificate is not a character reference. It shows that the connection to a particular name is encrypted; it does not investigate who registered that name or what they intend to do. Which is exactly why Google’s advice on a secure page is not “relax” but “check the site name in the address bar” — the name is the part a certificate cannot vouch for on your behalf.

For a page without HTTPS, Google’s advice is plain: “We suggest you don’t enter any private or personal information on this page. If possible, don’t use the site.” Note what it does not say — it does not tell you to fix anything, because there is nothing on your side to fix.

The setting that asks first. Chrome has an option called Always use secure connections. Google describes what it does plainly: with it on, “if a site doesn’t support HTTPS, Chrome displays a ‘Connection is not secure’ warning”. So instead of quietly loading an unencrypted page, the browser stops and asks. For anybody who would rather be told than assume, that is the one switch on this page worth changing — and it changes the default from silence to a question.

There is one more thing worth knowing about what the icons do and do not tell you, and Google mentions it in passing. Selecting the symbol opens “a summary of the site’s privacy details, cookies and site data, permissions, history of visits, and information about the page”. The icon is a door as well as a status — and behind it is the list of what that site has been allowed to do on your machine, which is a more useful thing to read than the icon itself.

What this page will not tell you is that HTTPS makes a site trustworthy. That is the specific confusion it exists to correct, and repeating it in softer words would defeat the purpose. Encrypted and honest are two different properties, checked by two different mechanisms, and only one of them is reported by a padlock.

Nor will it tell you how to get a certificate for your own site — that belongs to the floors on hosting and domains, where the practical arrangements live.

The floors below take it three ways: what the connection protects, what it does not, and the neighbouring things a browser reports about a page.

Where to start

Three ways in. If the question is “is this site safe”, take the second.

“What does the S actually add?”
One thing, precisely — what the s adds
“Is this site safe because it has a padlock?”
No — read what it does not say
“The browser says not secure.”
That is the site owner’s to fix — the four states

What the S adds

An encrypted connection, so that what you send and receive is private between you and the site. That is the whole of the difference, and it is a real one.

What it does not say

Nothing about who owns the site or what they intend. Google’s own advice on a secure page is to check the name in the address bar, which is the part no certificate covers.

The four states

Secure, not private, not secure, dangerous. Three describe the connection; only the last describes the site, and it comes from a different system.

What this tower will not do

It will not tell you a padlock means a site is trustworthy. Google prints a warning to keep checking the address directly beneath its own description of the secure indicator.

It will not treat the four browser states as four grades of safety. Three of them describe the connection and one describes the site, and they are not on the same scale.

And it will not tell you to work around a “not secure” warning. Google says the site owner is the one who has to fix it, and that there is nothing to enter on such a page in the meantime. What holds instead is simple: the descriptions of the secure, not private, not secure and dangerous states, the instruction to check the site name in the address bar even on a secure connection, the note that someone may view and change information sent over an unsecured connection, the statement that the site owner must secure the site with HTTPS, the advice not to enter personal information on an unsecured page, the Always use secure connections setting and its warning, and the summary of privacy details available behind the icon are quoted from Google’s Chrome help documentation, listed below.

Where this page got its facts

  1. Google, Check if a site’s connection is secure — Chrome Help (that the symbols beside the web address indicate whether Chrome has or has not established a secure and private connection with a site; that on a secure connection the information sent or received through the site is private between the user and the site, together with the instruction that even when connected securely one should always be careful when sharing sensitive or personal information and should check the site name in the address bar to make sure it is the intended site; that a site without a private connection may allow someone to view and change the information sent and received, that the site owner must secure the site and the user’s data with HTTPS, and that private or personal information should not be entered on such a page and the site avoided if possible; that a “not secure” state means something is wrong with the privacy of the site’s connection and that someone might be able to find the information sent or received; that a full-page red warning means the site has been flagged as unsafe by Safe Browsing, can misuse or abuse any information it receives and could attempt to install harmful software, and should not be used; that selecting the icon shows a summary of the site’s privacy details, cookies and site data, permissions, history of visits and information about the page; and that with the Always use secure connections setting turned on, Chrome displays a “Connection is not secure” warning when a site does not support HTTPS) — support.google.com, read 22 August 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 22 August 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.