In September 2023, Google removed the padlock icon from Chrome’s address bar. The icon had appeared in hundreds of billions of browser sessions, in every country, on every device, for more than a decade. It had been endorsed by the FBI, the FTC, the UK’s NCSC, and security educators worldwide as the primary visual signal that a website was safe to use. Google replaced it with a neutral tune icon and explained, in understated engineering language, that the padlock was misleading consumers.
The reason Chrome removed it was documented in data: by 2023, more than 90% of phishing sites displayed the padlock. The signal that had been positioned as a separator between safe and dangerous websites was present on both. It had lost its discriminative value completely.
And yet Keepnet Labs’ 2025 survey found that 44% of respondents were more likely to click a link when it showed a padlock. A symbol that means nothing about site safety continues to drive trust decisions for nearly half of all consumers. Baymard Institute’s 2024 research found that 25% of checkout abandonment events cite credit card security concerns, which suggests consumers are making security judgments at checkout, but the padlock they look for to resolve those concerns is present on both the legitimate checkout page and the phishing page targeting it.
This is not a story about consumer gullibility. It is a story about six cognitive mechanisms that behavioral economists have documented for decades, applied to a specific security symbol in a specific digital context. Understanding these mechanisms explains why the padlock remains psychologically sticky long after it became factually meaningless, and what that means for how web security communicates trust.
Mechanism 1: The Mere Exposure Effect
In 1968, Robert Zajonc published findings that would become one of social psychology’s most replicated results: simple repeated exposure to a stimulus increases liking and trust of that stimulus, independent of any rational evaluation of its properties. The effect operates below conscious awareness. Subjects shown abstract shapes more frequently rated those shapes as more pleasant than shapes shown less frequently, even when they could not identify which shapes they had seen before.
The padlock appeared in Chrome, Firefox, Safari, and Edge on every HTTPS page loaded since the mid-2010s, when HTTPS adoption crossed 50% of web traffic. By 2020, it appeared on more than 80% of pages. A user who spent two hours per day browsing the web encountered the padlock thousands of times per year. The association between padlock and safe browsing was conditioned at exactly the frequency Zajonc’s research identified as sufficient for strong preference effects.
The mere exposure effect does not require the association to be accurate. It requires only repetition. The padlock was accurate when it was trained into users: in 2015, an HTTPS padlock on a website was a meaningful signal because the effort and cost of obtaining a certificate served as a filter that separated well-maintained legitimate sites from hastily constructed phishing operations. Let’s Encrypt removed that filter in 2015. The conditioning continued after the signal became meaningless because users were still seeing the padlock on legitimate sites every day. The update to the mental model required active attention that the automatic exposure process did not provide.
The Zajonc effect helps explain why Chrome’s 2023 padlock removal was behaviorally necessary but insufficient. Removing the positive exposure stimulus stops further conditioning of trust. But it does not remove the ten years of prior conditioning already built into users’ automatic responses. The DecisionLab’s summary of mere exposure research notes that the effect persists even when subjects are told that their preference was caused by mere exposure. Knowing the mechanism does not undo it.
Mechanism 2: Authority Bias and Delegated Trust
Robert Cialdini’s framework for persuasion identifies authority as one of six core influence mechanisms: people defer to perceived experts and authorities, particularly on topics where they lack direct knowledge. Web security is precisely such a topic for most consumers. The technical mechanisms of TLS handshakes, certificate chains, and cryptographic key exchange are opaque to the vast majority of people who use HTTPS-secured sites every day.
The padlock was not just a symbol. It was an authority-endorsed symbol. The FBI published guidance telling consumers to look for it. The FTC included it in consumer protection materials. The UK’s National Cyber Security Centre recommended it. Google added a ‘Secure’ label alongside it in Chrome for several years. These authorities did not merely suggest the padlock was helpful; they positioned it as the primary mechanism consumers should use to evaluate website safety. When authorities with established credibility in a domain designate a specific heuristic, people adopt that heuristic as a substitute for their own evaluation.
The authority endorsement created what behavioral economists call delegated trust: the consumer outsources the evaluation question to the authority rather than performing their own assessment. ‘Is this website safe?’ becomes ‘Does this website have the symbol the FBI told me to look for?’ The second question is answerable with a glance. The first is not answerable without technical knowledge the consumer does not have.
Delegated trust is a rational response to information asymmetry. Consumers cannot evaluate TLS configurations or certificate validation levels. Using an authority-endorsed signal as a proxy is cognitively efficient. The problem is that the authority endorsement persisted in consumer memory long after the authorities updated their guidance. NCSC, FBI, and FTC have all updated their materials to remove or qualify the padlock recommendation, but the original endorsement was encountered far more frequently than the correction. Corrections reach a fraction of the audience that received the original message.
Mechanism 3: Visual Anchoring in Browser Chrome
Nielsen Norman Group’s research on web scanning behavior established that users follow consistent visual patterns when evaluating pages: they scan content in F-shaped or Z-shaped patterns, but they evaluate browser interface elements (the chrome: the navigation bar, address bar, and browser UI outside the content area) as a separate, higher-trust zone from page content.
This distinction matters for security evaluation. The padlock was displayed in the browser chrome, not in the page content. Users have learned, correctly, that page content can be controlled by the website operator and therefore cannot be unconditionally trusted. Browser chrome is controlled by the browser vendor and therefore carries higher baseline credibility. A padlock displayed by the browser is perceived as a statement the browser is making about the page, not a statement the page is making about itself.
This perception is accurate when the padlock signals something the browser has independently verified. It was accurate when DV certificates required effort to obtain. It became inaccurate when DV certificates became free and automated. But the browser chrome location continued to confer the credibility of browser-origin communication even as the underlying verification requirement dropped to near zero.
The anchoring effect from position compounds with the authority effect from Chrome’s branding: a symbol in the Chrome browser frame, from a Google product, carries both the browser’s trust halo and Google’s authority halo. The phishing site displaying that padlock is benefiting from Google’s credibility without Google having verified anything about the site’s identity.
Nielsen Norman Group’s research on trust indicators found that elements in the browser chrome receive less scrutiny than content-area elements, because users have learned that browser chrome is more reliable than content. This makes browser-chrome trust signals both more persuasive and more dangerous when they convey false assurance: the reduced scrutiny applied to browser chrome elements means the false signal is less likely to be questioned.
Mechanism 4: Cognitive Closure and the Security Question
Arie Kruglanski’s need for cognitive closure framework describes the psychological drive to reach a definite answer and move on from a question, resisting information that would reopen it. High need for closure is associated with reliance on heuristics, early commitment to initial impressions, and resistance to revising those impressions.
Security evaluation during a browsing session is a question with high need for closure. The cognitive load of maintaining a security question open across every page interaction is unsustainable. Users establish a security baseline quickly and then close the question to focus on the actual task. The padlock provides a closure mechanism: it converts the open question ‘should I trust this website?’ into a closed answer ‘yes, there is a padlock’ within a single glance.
The closure function of the padlock explains why its removal by Chrome created user discomfort even among technically sophisticated users who understood why it was removed. The tune icon that replaced it does not provide closure. It is a neutral indicator that requires interpretation rather than a binary safe/unsafe signal. Users lose the comfortable closure mechanism without receiving a clear replacement.
This also explains why DV-vs-OV is not a consumer-accessible distinction under normal browsing conditions. Distinguishing between them requires reopening the security question after the padlock has already closed it, navigating into certificate details, and interpreting the presence or absence of an Organization field. This multi-step process fights directly against the cognitive closure drive. The closure mechanism fires before the distinguishing information is accessed.
Mechanism 5: The Universality Paradox
Safety signals face a specific kind of decay as they become universal. A signal that separates the safe from the unsafe has value proportional to its discriminative power: the degree to which its presence correlates with the safe category and its absence correlates with the unsafe category. As adoption approaches 100%, the signal loses this discriminative power while retaining its psychological function as a reassurance cue.
Nutrition labeling is an instructive parallel. Mandatory nutritional labels on packaged food were introduced to help consumers make informed choices. Research has consistently found that label presence creates a general sense of product safety and regulatory oversight, even among consumers who do not read the labels. The label’s function shifted from information provision to reassurance signaling. Consumers feel that a labeled product has been checked by someone.
HTTPS adoption followed the same trajectory. In 2015, when 50% of pages were HTTPS, the padlock indicated that a site operator had made an active effort to secure their users’ connections. By 2025, when 88% of websites used HTTPS and Let’s Encrypt had issued over a billion free certificates, the padlock indicated only that a site existed and had an active server. Its informational content approached zero. Its reassurance function remained intact.
The paradox is that universality is itself a trust signal through a separate mechanism: social proof, another of Cialdini’s six principles. When everyone uses a safety measure, its absence becomes the signal. Consumers may not consciously evaluate the padlock’s presence as meaningful, but they notice its absence as alarming. The ‘Not Secure’ warning that browsers display for HTTP sites is more effective as a trust-reduction signal than the padlock ever was as a trust-addition signal. Loss aversion amplifies negative signals beyond the neutral baseline in ways that positive signals cannot achieve.
Mechanism 6: Loss Aversion and the Discomfort of Signal Removal
Kahneman and Tversky’s prospect theory established that losses are psychologically weighted approximately twice as heavily as equivalent gains. Removing a familiar safety signal, even a false one, is experienced as a loss rather than a correction, because the subjective experience is of reduced security rather than more accurate information.
Google’s Chrome team understood this when they removed the padlock. Their own research showed that fewer than 3% of navigations triggered a warning under the new HTTPS-First mode they introduced alongside the icon change. But qualitative feedback from users showed discomfort with the neutral tune icon not because it provided less accurate information but because it provided less reassurance. The familiar symbol of a decade of conditioning was absent.
Loss aversion in this context operates on the signal itself rather than the underlying security it represents. Users who encountered the neutral Chrome icon reported feeling less secure than they had with the padlock, even on sites with identical TLS configurations. The psychological cost of losing the familiar closure mechanism outweighed the rational benefit of receiving more accurate information about what the padlock had actually meant.
This creates a genuine design dilemma for browser vendors: any replacement for a false-positive safety signal will initially reduce perceived security, because the replacement provides less reassurance than the false signal did. The accurate signal that says ‘this connection is encrypted but we have no information about who operates this site’ is less reassuring than the inaccurate signal that said ‘this site is safe.’ The truthful update requires users to accept less comfort in exchange for more accuracy.
This is precisely the challenge that faces any attempt to communicate the DV vs OV distinction to consumers. OV certificates provide more accurate information about site identity than DV certificates. But communicating this distinction requires expanding the security question past the comfortable closure point of padlock presence. Users who have closed the security question with ‘padlock = safe’ must reopen it to process ‘padlock + Organization field = verified business identity’ vs ‘padlock without Organization field = unknown operator.’ The cognitive cost of this additional processing is real and most consumers will not pay it without strong motivation.
What Chrome’s September 2023 Decision Reveals About the Problem
Google Chrome’s removal of the padlock on September 5, 2023, in Chrome version 117, was a behavioral design decision as much as a technical one. Chrome Security engineer Chrissy Holbrook wrote the rationale: ‘the lock icon also doesn’t communicate meaningful information about the page’s trustworthiness, as it was never intended to. Users frequently interpret the lock icon as a signal of trustworthiness, when really it just indicates that the connection is secure.’
The technical statement is accurate. The behavioral statement is the more important one: users interpret the padlock as a trustworthiness signal rather than as a connection encryption indicator. This misinterpretation is not a user error. It is the predictable outcome of a decade of conditioning by browser vendors, security educators, and regulatory bodies who promoted the padlock as a trustworthiness signal before its informational content had been eroded by universal DV adoption.
Google’s solution, the neutral tune icon, addresses the problem from one direction: it removes the positive false signal. It does not address the conditioning that remains. Users who have associated padlock absence with danger will experience the new neutral icon as a degraded security state, even though the actual security state is identical. The behavioral residue of ten years of conditioning is not erased by a UI update.
The deeper implication is that browser vendors bear partial responsibility for the consumer trust gap that now benefits phishing operations. The green padlock and ‘Secure’ label that Chrome displayed from 2016 to 2021 actively trained users to treat DV certification as meaningful identity verification. The retraction of that signal in 2021 (green padlock removed) and 2023 (padlock removed entirely) does not undo that training. The phishing ecosystem that learned to exploit DV certification in 2018 is still exploiting the trained responses created by browser design decisions made between 2016 and 2021.
The System 1 Problem: What Would Have to Change
Daniel Kahneman’s dual-process framework distinguishes between System 1 thinking (fast, automatic, heuristic-based) and System 2 thinking (slow, deliberate, analytical). The padlock operates at System 1 speed: a glance, a pattern match, a closure. The certificate details page that reveals OV organizational identity operates at System 2 speed: three clicks, field identification, text interpretation.
Consumer security education has consistently tried to move security evaluation from System 2 to System 1 by creating a simple heuristic (look for the padlock) that can be acted on quickly. The heuristic worked when it was valid. Its failure is that it was too successful: it became the exclusive System 1 security signal, and when the signal’s validity eroded, no System 1 replacement was ready.
OV certificates contain the information that would differentiate legitimate business sites from phishing impersonations: a CA-verified organizational identity in the certificate Subject. But accessing this information requires a System 2 interaction sequence that most consumers will not perform. No browser currently surfaces the presence or absence of organizational identity in the address bar in a way that creates a System 1 trust signal equivalent to the old padlock.
The behavioral economics of web security therefore points to an unsolved design problem: how to surface a meaningful trust signal at System 1 speed for a distinction (verified business identity vs domain control only) that requires a System 2 process to establish. The OV certificate creates the verification. No browser creates the visible signal.
The most effective behavioral intervention for the current trust gap would be a browser-level indicator that distinguishes ‘connection encrypted, business identity verified’ from ‘connection encrypted, no identity verified’ at System 1 speed. This is technically achievable: browsers can read the Organization field in a certificate’s Subject before displaying the page. Several browser extensions implement variations of this. No major browser has implemented it as a default. The padlock’s removal created the design space for such a signal. The design problem is whether any new symbol can be trained into System 1 responses without repeating the conditioning-then-erosion cycle of the padlock.
The Irony That Makes This Commercially Significant
The behavioral mechanisms described in this article create a specific market dynamic that is commercially significant for any business that runs a checkout page. Consumers are making security judgments at checkout. Baymard Institute’s 2024 research shows 25% of checkout abandonment events cite credit card security concerns. Those consumers are using an evaluation heuristic (padlock present = safe) that cannot distinguish a verified business from a phishing site.
The result is that legitimate businesses with DV certificates lose customers to security-concern abandonment that their certificate type cannot address, while phishing operations use the same certificate type to pass the same consumer security check. The consumer’s heuristic fails both the security objective (it does not identify phishing) and the commercial objective (it does not reassure purchasers who are abandoning legitimate checkouts).
OV certificates break this equivalence. OV certification requires the Certificate Authority to verify the legal entity behind the site. Phishing operations cannot pass OV validation. Zscaler ThreatLabz 2024 documented that zero percent of phishing sites use OV certificates. The certificate type that could distinguish legitimate businesses from phishing infrastructure exists. It is used by approximately 5.5% of all websites. The behavioral mechanisms described in this article explain why it is not used more widely: consumers do not currently receive a System 1 signal from OV certificates that would create demand pressure for their adoption.
