Google plans to change Chrome's URL bar lock icon, introduced to signify HTTPS, to a “variant of the tune icon”, because “nearly all phishing sites use HTTPS”
Honestly, it's about time. … Tweets: Brian Jackson / @brianleejackson : Interesting. The HTTPS lock icon 🔒 is being replaced with a tune icon. Coming to a #Chrome near you. I remember writing about why you should migrate to HTTPS. We've come a long way since then. 😄 https://blog.chromium.org/... https://twitter.com/... Nick Sullivan / @grittygrease : Finally, the padlock era is coming to an end. https://blog.chromium.org/... @ow : (i'm fairly sure the chrome team are MUCH smarter than me and have clearly done their research on how the lock doesn't actually represent “trustworthiness” but it'll be interesting to watch this one) Addy Osmani / @addyosmani : With HTTPS now the norm, @googlechrome has reevaluated the lock icon 🔒 We will emphasize that security should be the default state and instead, evolve the icon to be more of a tune-up control for site settings. https://blog.chromium.org/... https://twitter.com/... https://twitter.com/... Stefan Judis / @stefanjudis : Do you remember when browsers started showing the URL bar lock to signal HTTPS? Fun fact: Chrome will remove it, because HTTPS is more or less the default now & the icon shouldn't be associated with the trustworthiness. No HTTPS will still be flagged.💪 https://blog.chromium.org/... https://twitter.com/... J. Alex Halderman / @jhalderm : Big news from Chrome Security Team! With HTTPS encryption now nearly ubiquitous, they're finally killing off the browser🔒icon, which tends to give users a false sense of security about other threats. https://blog.chromium.org/... A huge milestone for web security. h/t @davidcadrian @ow : Chrome is going to replace the 🔒 icon with a settings icon (!) which feels like a SPICY change when we spent the last 2 decades teaching users to look for the lock to be sure a site is secure! https://blog.chromium.org/... https://twitter.com/... Adam Levin / @adam_k_levin : “Misunderstandings are so pervasive that many organizations, including the FBI, publish explicit guidance that the lock icon is not an indicator of website safety.” https://www.bleepingcomputer.com/ ... Justin Elze / @hackinglz : Now that 99% of websites loaded by Chrome use https how big of a security improvement did it make? https://www.bleepingcomputer.com/ ... Dion Almaer / @dalmaer : Times they are a changing. I remember when the largest conversion bump at Walmart was adding the photo of a lock 🔒:) https://blog.chromium.org/... @zooko : The best UX improvement is when you eliminate UI about the thing completely, because the user is correctly assuming that the thing is there. In what I regard as an historic moment, Chrome removes the 🔒 icon that was used to indicate HTTPS: https://blog.chromium.org/...
Context & Ripple Effects
The padlock's retirement closes a nine-year arc that Chrome itself drove. The security team first floated treating plain HTTP as non-secure back in December 2014, moved to a red "x" over the padlock in January 2016, and then flipped the default in July 2018 with Chrome 68 marking every HTTP site "not secure" — a campaign so successful at pushing encryption everywhere that it destroyed its own signal.
First-order effects
- Site owners and security trainers lose the padlock as a teaching shorthand overnight: Chrome users will see a tune icon that conveys connection settings, not safety, and any guidance built on "look for the lock" goes stale.
- Phishing sites lose nothing and gain ambiguity — since nearly all of them already deploy HTTPS, the change removes an indicator they were inadvertently failing anyway.
Second-order effects
- Other browser vendors face pressure to follow Chrome's lead or defend why their URL bars still display a trust symbol Google has deemed misleading — the same follow-the-leader dynamic that spread the original HTTP-shaming banners.
- Certificate authorities and HTTPS-peddlers see the last consumer-facing marketing value of the padlock erode; encryption becomes table stakes invisible to users rather than a differentiator to advertise.
Third-order effects
- If browsers stop signaling transport security in the URL bar entirely, trust signals migrate toward site identity and provenance — pushing vendors toward richer origin indicators and leaving room for regulators and platforms to define what "verified" means.
- It also continues a pattern where Google quietly reworks its biggest user-facing interface elements — as with the Chrome 69 forced-login backlash — meaning each such change now carries a trust-burning cost the company has to manage.
The trend: Browser security UI is shifting from celebrating encryption adoption to de-emphasizing it as ubiquitous, moving trust signaling from transport-layer icons toward site identity itself.