HTTPS Guarantees Three Things, But Users Expected More
HTTPS provides authentication, encryption, and data integrity. Authentication means the website is who it says it is, not that it’s trustworthy. Chrome’s 2021 user study found 89% of participants overestimated what the lock icon guaranteed. Over half thought it meant safe to enter data. Almost half thought the website was trustworthy in general. Only 11% got it right. The lock icon became dangerous miscommunication. An FBI PSA in June 2019 explicitly told people not to trust a website just because it has a lock.
The Decade-Long Push to Make HTTPS Normal
Edward Snowden’s 2013 revelations about mass surveillance galvanized the tech industry. Before that, HTTPS traffic was rare. Let’s Encrypt telemetry showed 27% of page loads used HTTPS in 2014. Google then used HTTPS in search rankings. Let’s Encrypt offered free certificates in November 2014, removing a major roadblock. Chrome adjusted security indicators over time. Insecure connections once normal became warnings. HTTPS itself went from celebrated to quiet. The optimal design for security UI changes with adoption context.
The 1% Experiment and Security Theater
Chrome ran a 1% experiment swapping the lock icon for a neutral tune icon. Users noticed and clicked to investigate, but no regressions occurred on HTTPS pages or form submissions. To differentiate reassurance from dangerous theater, the team looked at behavior. The lock icon made people more likely to click phishing links. That put it squarely in security theater. Other examples: TSA failure rates of 80-95%, private VPNs that snoop, forced password rotation leading to post-it notes.
Ecosystem Change Takes Time
After 30 years, HTTPS is now so common that Chrome removed the lock icon. The change represents a decade’s work by hundreds of people across companies. The lock icon was a 16x16 pixel square that signaled the end of that effort. The web platform taught that big problems require persistence. The same approach applies to inequality, climate change. Solve problems one by one. Keep pushing in the right direction.
Q&A
Why replace the lock icon instead of just removing it? The tune icon still provides access to certificate details, site permission controls, and toggles. ▶ 20:35
What was the initial reaction from users? Mostly “this is very silly” but follow-up reactions became understanding after noticing that insecure connections still show a prominent warning. ▶ 21:49
How costly was the change? Very cheap in effort — a glyph change; no major behavioral changes needed. ▶ 22:50
Would Chrome surface a lock icon for quantum key exchange? It depends on the risk; currently Chrome is preparing underlying systems for larger keys, but UI changes will only come if the risk is significant. ▶ 23:46
Notable Quotes
The lock icon is no longer there. Serena Chen · ▶ 0:35
only about 11% correctly identified the guarantees made by the lock icon Serena Chen · ▶ 6:57
So security theater can be actively harmful. It can lull you into a false sense of security Serena Chen · ▶ 13:24
And so more than 30 years after the creation of HTTPS, it is now so common that Chrome can finally remove the lock icon. Serena Chen · ▶ 16:50
Key Takeaways
- Chrome’s lock icon misled 89% of users; removing it was supported by user behavior data.
- The HTTPS adoption journey spanned over a decade, driven by Snowden revelations and free certificates.
- Big ecosystem changes require persistence; security theater must be identified through observed behavior.
About the Speaker(s)
Serena Chen is an ex-physicist and mathematician, once teen magazine editor-in-chief, foosball enthusiast and hacker at heart. For her day job she’s the Staff UX Lead for Chrome Security.