Why the chain matters more than the padlock itself
The padlock only confirms the connection is encrypted and that some certificate authority vouched for the domain β it says nothing about whether the site itself is trustworthy or legitimate. Scam sites can and do hold valid DV certificates, since domain validation checks control of a domain, not the intent of whoever controls it.
Why EV certificates faded from browser UI
Browsers used to show a green company name next to the padlock for EV certificates, but most major browsers removed that distinct visual treatment because research suggested it did not meaningfully help users spot scams, and displaying it inconsistently across sites created more confusion than clarity.
Frequently Asked Questions
Does HTTPS mean a site is safe to trust?
It means the connection between you and the site is encrypted and the certificate is valid for that domain β nothing more. It says nothing about whether the site itself is legitimate, so phishing sites frequently use valid HTTPS certificates too.
What happens when a certificate expires?
Browsers block the site with a warning page until the certificate is renewed, since an expired certificate can no longer be trusted to prove the connection is genuinely secure. Most sites now automate renewal specifically to avoid this happening.