Google plans to change Chrome's URL bar lock icon, introduced to show HTTPS, to a “variant of the tune icon”, saying HTTPS is now present on malicious websites
Google announced today that the lock icon, long thought to be a sign of website security and trustworthiness …
Context & Ripple Effects
Chrome’s security UI has steadily moved from rewarding encryption to warning about its absence: Google first considered marking HTTP pages non-secure, then Chrome 68 made the “not secure” warning for HTTP sites broadly visible.
This change completes that arc by treating HTTPS as a baseline transport property rather than a trust badge. It matters because the browser’s address bar shapes what users infer from a site before they evaluate its content or identity.
First-order effects
- Chrome users will see a tune-style site-controls indicator in place of the lock, reducing the chance that encryption alone is read as an endorsement of a site.
- Site operators retain HTTPS as an expected security baseline, but lose the lock icon’s incidental value as a visible trust signal.
Second-order effects
- Anti-phishing guidance and browser safety messaging will need to emphasize signals beyond the address-bar icon, since malicious sites can also use HTTPS.
- Other browser makers may reassess security indicators that still imply a stronger trust judgment than encrypted transport can support.
Third-order effects
- Browser UI is shifting from binary security labels toward contextual controls: encryption protects the connection, while trust increasingly depends on separate signals such as identity and harmful behavior.
- If this pattern holds, HTTPS becomes less of a competitive reassurance feature and more of an invisible minimum standard, as Chrome’s earlier removal of the green “Secure” label anticipated.
The trend: The broader trend is the normalization of HTTPS and the redesign of browser security interfaces to distinguish connection security from website trustworthiness.