BlogGuides
The padlock icon is not enough: what HTTPS really means

One click, and Google will show my articles more often in your results.
Anyone trying to confirm that a site is safe usually checks the same thing: the closed padlock next to the address, maybe the letters "https" before the domain name. It's an understandable habit, taught for years as a rule of thumb. The problem is that symbol tells you far less than it seems to, and since 2023 Google itself has said so openly by changing how it's shown.
What it actually confirms, and what it doesn't
The padlock certifies exactly one thing: that data exchanged between the browser and the site travels encrypted along that connection, making it hard for anyone intercepting it along the way to read. It says nothing about who runs the site, whether the business behind it is real, or whether it deserves trust. That's the same distinction Italy's State Police draws in its own guidance on online shopping, where the padlock and the letters https are presented as confirmation that the data sent during a payment stays confidential, never as proof that the seller is genuine: two different things, often mistaken for the same one.
Why a phishing site can carry the same padlock
Getting a certificate that turns on the padlock requires no check at all on who is requesting it: just a domain name, and for years free certificate authorities have issued one in minutes. The official Chromium blog put it plainly on May 2, 2023: "nearly all phishing sites use HTTPS, and therefore also display the lock icon." It's not an isolated remark. As early as June 10, 2019, the FBI, through its Internet Crime Complaint Center, published an alert on exactly this, with a direct recommendation: "do not trust a website just because it has a lock icon or 'https' in the browser address bar." Advice aimed at everyday browsing, but just as relevant when judging a supplier or a partner found online.
Why even Chrome took it away
The misunderstanding isn't a footnote: it's the reason Google changed the icon itself. In its official Chromium blog post, the team cited a 2021 study finding that only 11% of the people surveyed correctly understood what the symbol actually meant, and noted that several organizations, including the FBI, have long published explicit guidance that it shouldn't be read as proof a site is safe. Starting with Chrome 117, which arrived in early September 2023, the padlock disappeared from the desktop address bar, replaced by a neutral tune icon that opens the site's settings: an encrypted connection, according to Chrome, should be the normal state of every site, not a badge worth showing off.
The guarantee
Thirty days to change your mind.
In more than ten years I have never had a client unhappy with the work delivered. That is why I can afford to say this: you have 30 days from accepting the quote to stop, or until the site goes live if that comes first. Within that window I refund everything you have paid and we part ways, with no further claim and no argument. There are no conditions to meet and nothing to prove: you decide.
You get me, within one working day.
No switchboard, no support form. If you write or call and I do not answer within one working day, you do not pay that month.
I take the risk at the start. It is the only way I have to say “trust me” and have it mean something.
What actually to look at before you hand over your details
If the padlock isn't enough, what's left to check is simpler than it sounds, and it's exactly what a fly-by-night site rarely bothers to get right: a verifiable legal name and registration number, a real address, a way to be contacted that isn't just a form that never gets answered. It also flips the usual assumption about reviews: the ones published on the site itself count for less than the ones you can read elsewhere, on a profile or platform the business doesn't fully control, precisely because a text a company can write and delete on its own proves about as much as the padlock alone: not much.
And if your own site is missing the padlock
The same logic runs the other way too: if your site doesn't have HTTPS yet, it's no longer a technical detail you can put off. On February 8, 2018, Google announced on its own security blog that with Chrome 68, released that July, the browser would flag any page without HTTPS as "not secure," including pages without forms or payments: since then, that message shows up for anyone who visits, customer or not. The reassuring part is that fixing it now costs little or nothing: most modern hosting includes a certificate that renews itself automatically, as I explained writing about expired certificates and about what hosting should actually include. It isn't a feature worth bragging about anymore: it's the baseline everything else gets built on.
If you'd like an honest read on what your site actually signals to someone landing on it for the first time, get in touch and we'll look at it together.