Why the green padlock (HTTPS) does not mean a website is safe
Last updated:
For over a decade, security advice repeated the same rule: “Always check for the green padlock before entering your credit card”. Today, that rule has become a trap: over 80% of active phishing websites display a perfectly valid SSL padlock.
What HTTPS actually does (and what it does not)
HTTPS ensures data transit confidentiality: nobody between your computer and the remote server can intercept the packets. However, if the server belongs to an internet fraudster, your data travels securely right into the hands of a criminal.
Encryption vs Verified Authenticity
| Security attribute | Guaranteed by HTTPS padlock | Required to avoid online scams |
|---|---|---|
| Password encrypted in transit | Yes (safe from Wi-Fi sniffers) | Yes |
| Verified legal business identity | No (certificates are automated and anonymous) | Yes (only verified domains count) |
| Absence of malicious scripts on page | No (page can still contain keyloggers) | Yes (DOM and script analysis) |
| Legitimate payment request | No (any scammer can host a card form) | Yes (contextual verification) |
Why SSL certificates cost nothing to cybercriminals
- Universal automation: free certificate authorities issue HTTPS certificates in under 30 seconds with zero identity verification.
- Ephemeral hosting: attackers spin up domains in the morning, get certified at noon, and run their scam campaign in the afternoon.
- Technical neutrality: certificate authorities have no authority or technical ability to judge whether a site is a genuine store or a phishing trap.
Effective signals for verifying website authenticity
- Exact domain spelling: scrutinize TLD extensions and every letter in the domain name.
- Domain registration age: newly registered domains asking for payments are high risk by default.
- Inbound context: if you arrived via an unsolicited SMS or urgent email, exercise extreme caution.
- Verified company disclosures: look for verifiable registration numbers, physical business addresses, and terms of service.
How Resku addresses the padlock blind spot
Resku is not misled by brand-new SSL certificates. The extension analyzes domain age, page layout mimicry, known brand elements, and form behaviors in real time (~200 ms) to deliver an objective trust score.
Official references
- ANSSI / CISA : guidance on TLS implementation and deceptive certificate perception.
- Cybermalveillance.gouv.fr : educational guides on the limits of HTTPS padlocks.
- Chromium Security Blog : reasons behind changing the browser padlock icon.
Frequently asked questions
Does HTTPS or a green padlock icon prove that a website is safe?
No. The HTTPS protocol and padlock icon only prove that communication between your browser and the server is encrypted. It prevents eavesdropping on your network, but says nothing about the honesty or legitimacy of the website owner.
Why do most scam websites display a valid padlock today?
SSL certificates are now automated and issued free of charge in seconds. Any malicious actor can register a fraudulent domain name and instantly obtain a valid SSL certificate.
What should you check instead of relying on the padlock?
Check the exact spelling of the domain name (look out for character swaps, risky extensions like .top or .info), examine legal business disclosures, domain age, and artificial urgency tactics.
How have modern web browsers updated the padlock indicator?
Due to widespread user confusion, Google Chrome and other major browsers removed the green highlight and replaced the padlock with a neutral tune icon to prevent users from mistaking encryption for verified trust.
Do not rely on the padlock icon to judge website legitimacy. Resku evaluates real domain reputation, underlying code, and fraud traps before you type.
Join the waitlist