"the padlock means the site is safe"

lore

securityweb dev

The padlock proves the connection is encrypted to whoever holds that domain - it says nothing about who they are. Phishing sites get certificates in minutes, for free.

By the late 2010s most phishing pages served valid HTTPS; the FBI issued a public advisory in 2019 warning that the lock icon is not a trust signal. Browsers have been quietly demoting the padlock since.

The padlock means the connection to this site is encrypted and the certificate matches the name in the address bar. It has never meant the site is safe, honest, or who you assume it is, and the gap between those two readings has been exploited for years.

The reason the misunderstanding became dangerous is that certificates became free and automatic, which was the right outcome for the web and removed any correlation between having a certificate and being legitimate. A phishing site gets a valid certificate in minutes, so the majority of phishing pages now display exactly the same padlock as the bank they are imitating, and a user taught to look for it is being taught a check that no longer discriminates.

Browsers responded by de-emphasizing it, which is why the padlock has been shrinking, greying, and in some browsers being replaced entirely. The check that actually matters is the domain name, read carefully, character by character, with attention to lookalike characters and to what comes immediately before the first single slash. That is harder to teach and it is the only part that tells you where you are.

Disputed / commonly mistold A popular version of this story is inaccurate - see the note above.

Also known as: padlock myth, green lock

Sources

  • FBI IC3 PSA I-061019-PSA - HTTPS phishing (2019)
  • APWG Phishing Activity Trends Reports - HTTPS share of phishing sites

All glossary entries