Home
Blog
HTTPS Doesn't Mean Safe: The Padlock Myth Explained

HTTPS Doesn't Mean Safe: The Padlock Myth Explained

Reviewed by
Table of Contents

Key Takeaways

For years, the advice was simple, memorable, and everywhere: "Before you enter your password or credit card number, look for the padlock." It appeared in bank onboarding emails, school cybersecurity curricula, government websites, and IT training decks. If you saw that little lock icon in the browser's address bar, you were safe.

There's just one problem: that advice is now actively dangerous.

The padlock hasn't gone away, but the protection it was supposed to signal has been thoroughly dismantled by cybercriminals. Today, the overwhelming majority of phishing sites display that exact same padlock. They are, by the technical definition, "secure." And yet they exist for one purpose: to steal your credentials, your money, or your identity.

It's time to retire the padlock myth, and understand what actually keeps you safe online.

What the padlock actually means

When a website uses HTTPS (HyperText Transfer Protocol Secure), it means that the data traveling between your browser and that website's server is encrypted. A third party sitting between you and the site (say, someone on the same public Wi-Fi) cannot read or intercept that data as it moves.

That's it. That's all the padlock guarantees.

It does not mean:

  • The website is legitimate
  • The business behind it is real
  • The people running it have good intentions
  • Your personal data won't be stolen once it arrives

As John LaCour, then-CTO of cybersecurity firm PhishLabs, put it bluntly back in 2018: "The bottom line is that the presence or lack of SSL doesn't tell you anything about a site's legitimacy."

Think of it this way: HTTPS ensures the tunnel is private. It says nothing about what's waiting for you at the other end.

The numbers that should alarm you

This isn't a theoretical problem. The numbers are stark:

  • Back in 2018, PhishLabs found that 49% of all phishing sites already displayed the padlock, up from just 25% the year before.
  • By Q1 2019, the FBI reported that figure had climbed to 58% of tracked phishing sites.
  • Today, estimates put the share of phishing sites using HTTPS at over 74%, and some security researchers say it's closer to nearly all of them.

Meanwhile, phishing itself is exploding. The Anti-Phishing Working Group (APWG) tracked 3.8 million phishing attacks in 2025 alone, with Q2 2025 recording over 1.1 million attacks in a single quarter.

And yet the myth persists. A PhishLabs survey found that more than 80% of people believed the green padlock meant a website was legitimate and/or safe. Attackers know this. It's a feature, not a bug: they display the padlock because you've been conditioned to trust it.

How cybercriminals got the padlock for free

Here's the part of the story most people don't know: getting a padlock used to cost money.

In the early days of HTTPS, an SSL certificate, the technical credential that enables the padlock, required a paid verification process. The cost and friction served as a weak but real barrier. Most criminals weren't interested in jumping through hoops for a phishing page that might live for only 48 hours.

Then, in 2016, a nonprofit certificate authority called Let's Encrypt launched, backed by major tech organizations. The mission was genuinely good: make HTTPS free and automatic for the entire web, so every legitimate site could encrypt its traffic. It worked brilliantly. By 2023, Google reported over 95% of page loads in Chrome on Windows were using HTTPS.

But it also opened the floodgates for attackers.

A 2017 analysis found that Let's Encrypt had issued 15,270 SSL certificates containing the word "PayPal", and of those, a staggering 14,766 (96.7%) were issued to domains hosting phishing sites. Why? Because Let's Encrypt only checks whether you control a domain. It doesn't verify who you are or what your website does.

With a free SSL certificate obtainable in minutes, a padlock is no longer a sign of investment, verification, or legitimacy. It's a checkbox that anyone, including criminals, can tick.

Even Google admitted the padlock was broken

The clearest signal that the padlock myth had run its course came from an unlikely place: Google itself.

In September 2023, Google removed the padlock icon from Chrome's address bar entirely, replacing it with a neutral settings icon. The move had been in the works for years, but Google's own blog post explaining the change was a remarkable admission of failure:

"We know that the lock icon does not indicate website trustworthiness... nearly all phishing sites use HTTPS, and therefore also display the lock icon. Misunderstandings are so pervasive that many organizations, including the FBI, publish explicit guidance that the lock icon is not an indicator of website safety."

Google's internal research in 2021 found that only 11% of users correctly understood what the lock icon actually meant. The other 89% were operating under a false sense of security.

The FBI, for its part, had already issued a public warning in June 2019, explicitly telling users: do not trust the HTTPS padlock as an indicator of website safety.

When both the FBI and the world's largest browser maker are publishing warnings about a symbol they helped popularize, it's time to pay attention.

The tricks phishers use (beyond just the padlock)

Armed with a free SSL certificate, phishers deploy a range of techniques to make their sites indistinguishable from the real thing:

Typosquatting

Registering domains with common misspellings: paypa1.com, g00gle.com, amazonn.com. At a glance, especially on a mobile device, these look identical to the real domains.

Homograph attacks

Internationalized Domain Names (IDNs) allow non-Latin characters in URLs. Attackers exploit this by substituting characters that look visually identical but are technically different. One documented example: a phishing site for crypto exchange Bibox used the Vietnamese character instead of the letter i, rendering as bịbox.com in some browsers, complete with a valid padlock.

Subdomain abuse

Attackers can use the real domain as a subdomain of their own fake domain: paypal.com.login-verify.scam-domain.net. The real brand name appears prominently in the URL. The padlock is present. But the actual domain is the last one in the chain.

Brand impersonation on legitimate platforms

Phishing content hosted on legitimate platforms (Google Docs, Dropbox, GitHub Pages) inherits the platform's HTTPS certificate. The padlock is 100% genuine. The content is not.

What to actually look for instead

The padlock isn't useless. It still means your connection is encrypted, which matters on public Wi-Fi. But it can no longer be your primary trust signal. Here's what actually works:

1. Read the full domain, carefully.

Don't glance at the padlock. Read the entire domain in the address bar, character by character. Look for transposed letters, numbers replacing letters, or extra words tacked on.

2. Check the domain's age.

Brand-new domains are a significant red flag. You can run a quick WHOIS lookup at whois.domaintools.com to see when a domain was registered. A "PayPal security alert" site registered last Tuesday should stop you cold.

3. Type URLs directly or use bookmarks.

If you get an email claiming to be from your bank, don't click the link. Open a new tab, type the URL directly, or use a saved bookmark.

4. Use a password manager.

Password managers fill credentials only on the exact domain they're associated with. If you land on paypa1.com instead of paypal.com, your password manager won't auto-fill, because it knows something is wrong, even if you don't.

5. Use dedicated web protection tools.

Real-time URL scanning tools analyze sites as you visit them, catching threats that static blocklists miss. Guardio, for example, scans sites before you interact with them and flags suspicious domains that look legitimate but aren't.

We're still teaching the wrong lesson

Here's what makes this situation especially dangerous: the padlock myth isn't just a personal misconception. It's still being institutionally taught.

Many government websites, including some official cybersecurity guidance pages, still instruct users to "look for the padlock" as a primary safety check. School curricula, corporate security training modules, and well-meaning IT departments continue to repeat the advice.

The gap between what security researchers know and what average users are taught is measured in millions of compromised accounts. Every time someone enters their password on a phishing site and pauses only to check for the padlock, that gap has a real-world cost.

The cybersecurity community has largely moved on. The consumer awareness conversation hasn't caught up.

Conclusion

The padlock tells you one thing: your connection to this website is encrypted. That's valuable, but it's a floor, not a ceiling.

It does not tell you whether the website is run by a legitimate business, whether your data is safe once it arrives, or whether the person on the other end is who they claim to be.

Cybercriminals figured this out years ago. They get free SSL certificates in minutes, spin up convincing fake sites, and count on the fact that you were taught to check for the lock.

The best protection isn't a symbol in an address bar. It's a combination of skepticism, habits, and tools: reading URLs carefully, using a password manager, and relying on real-time security software that analyzes sites beyond just whether they have a certificate.

The padlock is not a green light. It's just proof the road has asphalt.

Stay skeptical. The internet's best phishing sites all have padlocks.

Get a free security scan with Guardio today and catch phishing sites before you enter a password.

CMS-based CTA:
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

Does HTTPS mean a website is safe?

HTTPS means your connection to the website is encrypted, not that the website itself is safe. Phishing sites can and do use HTTPS. Over 74% of phishing sites now display the padlock icon, meaning encryption provides no guarantee that the site is legitimate or that your data won't be stolen.

Can phishing sites have HTTPS?

Yes. The majority of phishing sites now use HTTPS. Free SSL certificates from services like Let's Encrypt are available to anyone, including criminals, in minutes. The padlock only confirms the connection is encrypted, not that the site is trustworthy or run by a legitimate organization.

Why did Google remove the padlock icon from Chrome?

Google removed the padlock icon from Chrome in September 2023 because it consistently misled users. Google's own research found that only 11% of users correctly understood what the lock meant. Since nearly all phishing sites also display the lock, Google replaced it with a neutral settings icon to stop false trust signals.

What should I look for instead of the padlock to know if a site is safe?

Read the full domain name carefully for misspellings or extra characters, type URLs directly instead of clicking email links, use a password manager that won't auto-fill on fake domains, and use real-time web protection tools that scan sites as you browse. These habits catch threats that the padlock never could.

What is the HTTPS padlock myth?

The HTTPS padlock myth is the widespread but incorrect belief that the lock icon in a browser's address bar means a website is safe and legitimate. In reality, the padlock only confirms the connection is encrypted. Cybercriminals use free SSL certificates to display the padlock on phishing and scam sites, making the icon an unreliable safety signal.

Is it safe to enter my credit card on an HTTPS site?

HTTPS alone is not enough to confirm it's safe. While HTTPS encrypts your data in transit, it doesn't verify the site is run by a legitimate business. Before entering payment information, verify the domain is spelled correctly, check that the site has a real contact page and privacy policy, and use a real-time security tool to scan the site.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now