You click an old link to a local club's website. Instead of the page, Chrome puts a box in front of the tab: "This site doesn't support a secure connection", two short warnings and two buttons, Go back and Continue to site. On other pages you only notice "Not secure" next to the address, and clicking it opens a panel that says "Connection is not secure". Nothing on your computer is broken, and you have most likely not been hacked.
This guide explains what the warning means, how it differs from "Your connection is not private", why Chrome shows it to more people since autumn 2026 and when it is fine to continue. It also covers router and Wi-Fi login pages, other browsers, site owners and proxies.
What does "Connection is not secure" mean?
Web addresses start with http:// or https://. With HTTPS, the page and everything you send are encrypted between your browser and the site, and the browser checks the site's certificate, a digital ID card that proves it reached the right server. With plain HTTP there is no encryption and no ID check: the page travels as readable text.
Everything that text passes through can read it, and change it: the Wi-Fi network, other devices on an open network, your internet provider or a proxy in between. Chrome marks such pages with Not secure in the address bar; click it and the panel says "Connection is not secure" and warns that passwords or credit card numbers entered there could be stolen.
The warning describes the connection, not the site's honesty. A hobby page and a fake bank page can both run on HTTP.
Is it the same as "Your connection is not private"?
No, and the two need different responses:
| What you see | What it means | Encrypted? | What to do |
|---|---|---|---|
| Not secure in the address bar | The page uses plain HTTP | No | Read, type nothing private |
| "This site doesn't support a secure connection" | Chrome tried HTTPS, found none and asks first | No, if you continue | Decide per site |
"Your connection is not private" + NET::ERR_CERT_… code | HTTPS exists, the certificate failed a check | Identity unproven | Stop on login and payment pages |
| "This site can't provide a secure connection" | The encrypted connection could not be set up | No connection | Check software, network or site |
The certificate warning is about a site that offers encryption but cannot prove who it is; a wrong clock, a Wi-Fi login page or antivirus scanning are the usual causes, as Your Connection Is Not Private Error: Causes and Fixes explains. The HTTP warning is simpler: the site offers no encryption at all, so there is nothing on your device to fix.
The last row, usually shown with ERR_SSL_PROTOCOL_ERROR, is a failed handshake, the opening exchange in which browser and server agree on encryption; see How to Fix err_ssl_protocol_error in Chrome and Edge.
What does Chrome's new warning say?
Chrome opens a dialog over the page titled "This site doesn't support a secure connection", with two points:
- "Attackers can see and change information you send or receive from the site."
- "It's safest to visit this site later if you're using a public network. There is less risk from a trusted network, like your home or work Wi-Fi."
The buttons are Go back and Continue to site. The warning can also fill the whole tab, with the heading "example.com doesn't support a secure connection with HTTPS" and the tab title "Site is not secure". These texts come from Chromium, the open-source code behind Chrome.
One variant deserves suspicion: "You usually connect to this site securely, but Chrome couldn't use a secure connection this time". The site normally works over HTTPS, and something on the network may be blocking it, so go back and try later or on another network.
Why did Chrome start asking before HTTP sites?
Google announced in October 2025 that Chrome would turn its Always use secure connections setting on by default for public sites, starting with Chrome 154 (Google's announcement), which reached the stable channel on 22 September 2026. Until then Chrome warned mainly in Incognito windows, on sites you normally open over HTTPS, and for people using Enhanced Safe Browsing.
Google rolls such defaults out in stages, so two computers with the same version can behave differently for a while. Because most of the web already uses HTTPS, Google says the median user sees fewer than one warning a week.
How does Chrome decide whether to warn?
The check runs on every address you open:
- You click a link or type an address, with or without
http://. - Chrome first tries the secure
https://version of the same address. - If the site answers properly over HTTPS, the page opens and you see nothing special.
- If HTTPS fails, Chrome checks whether the address is private:
localhost, a home-network number such as192.168.1.1, or a one-word name such asintranet/. In the default mode these load over HTTP without a warning. - For a public site you have not allowed recently, Chrome shows the warning and waits.
- If you press Continue to site, the HTTP page loads with Not secure in the address bar, and Chrome remembers the choice for that site.
Step 2 is why many old http:// links now quietly open as HTTPS. The permission in step 6 covers one site and is renewed each time you visit, so Chrome stops asking about a site you use regularly. The page itself stays unencrypted.
When is it safe to continue?
Ask two questions: what will I do on this page, and which network am I on?
- Reading only, on your home or mobile network: generally fine. A club calendar or a product manual carries little risk.
- Anything with a password, card number, address or ID details: go back and use the organisation's app or another way to reach it.
- Downloads: get the file from the vendor's HTTPS site or an official app store. On HTTP, someone on the path can replace it.
- Café, hotel or airport Wi-Fi: follow Chrome's advice and visit later from a trusted network. Open networks are where reading and changing traffic is easiest; Is Public Wi-Fi Safe? explains what the network owner can see.
Why do router pages and Wi-Fi login pages trigger it?
Routers, NAS boxes and printers are usually managed through a page at an address such as 192.168.0.1, and most use plain HTTP, because public certificate authorities do not issue certificates for private addresses. Chrome's default mode leaves these addresses out: the page shows Not secure but no warning. You do get the warning if you chose the stricter option for private sites, or if the device is opened through a name that looks like an ordinary web address. Continuing is fine at home on your own device.
Hotel and café networks often send you to a login page, a captive portal, before letting you online, and many of these use plain HTTP. Chrome opens the portals it detects in its own sign-in tab, without the HTTP warning. If you open the login page yourself and Chrome asks, continue, since there is no other way onto that network, and type only what it asks for, such as a room number or voucher code.
How do you check the "Always use secure connections" setting?
Leave the setting on and continue for single sites when you need to. Google's steps in Manage Chrome safety and security show where it is:
- Computer: at the top right, More > Settings > Privacy and security > Security, then Always use secure connections under "Secure connections".
- Android: More > Settings > Privacy and security, then Always use secure connections under "Security".
- iPhone and iPad: More > Settings > Privacy and security > Always use secure connections.
On a computer and on Android you can choose Warns you for insecure public sites, the default, which leaves out private sites such as a company intranet, or the stricter Warns you for insecure public & private sites. At work, IT can set this for everyone through Chrome's HttpAllowlist and HttpsOnlyMode policies, so ask them if an internal tool keeps warning.
How do Firefox, Safari and Edge show it?
Every browser follows the same idea in its own words; the texts below come from each browser's own text files or help pages.
| Browser | On an HTTP page | Before the page opens |
|---|---|---|
| Firefox | Not Secure; its tooltip: "Connection is not secure" | Only in HTTPS-Only Mode: "Secure Site Not Available" |
| Safari | Not Secure; also "Website Not Secure", "This Connection Is Not Secure" | No separate HTTP warning |
| Edge | Not secure in the address bar | Chromium's wording, such as "doesn't support a secure connection with HTTPS" |
Firefox tries HTTPS first and quietly falls back to HTTP when a site has none, so by default it does not stop you. Its stricter mode is under Settings > Privacy and security > HTTPS-Only Mode. Inside login fields on HTTP pages it adds: "This connection is not secure. Logins entered here could be compromised."
Apple's page on Safari's "Not Secure" warning puts four cases under these labels, including an expired or invalid certificate and an outdated TLS version, and its advice holds in every browser: never enter your password or credit card number on a site with this warning. In Safari, "This Connection Is Not Secure" can also mean a certificate problem, so check whether the address starts with http://.
If it's your website: how do you remove the warning?
Visitors cannot fix this; only the site can:
- Get a certificate. Most hosting panels issue free ones in a few clicks, usually from Let's Encrypt, a non-profit certificate authority.
- Serve every page over HTTPS and test each type of page at its secure address.
- Redirect HTTP to HTTPS with a permanent (301) redirect, so old links and bookmarks land on the secure version.
- Fix mixed content: images, scripts or forms that still load from
http://addresses. - Add HSTS once HTTPS works everywhere. HSTS (HTTP Strict Transport Security) is a response header such as
Strict-Transport-Security: max-age=31536000that tells browsers to use only HTTPS for your domain for that many seconds.
Take step 5 slowly. Once browsers have stored the header, they refuse plain HTTP for your domain and offer no way past certificate errors, as RFC 6797 requires. Start with a short max-age, and add includeSubDomains only when every subdomain has a working certificate.
What does a proxy or VPN change?
The warning looks the same with or without a proxy, because it is about the site, not the route. A proxy neither causes it nor removes it.
What changes is who can read the traffic. On an HTTP page the proxy receives the full request: the address, cookies and anything typed into forms. On an HTTPS page the browser asks the proxy for a tunnel with a CONNECT request, and the proxy then only does "blind forwarding" of encrypted data, in the words of RFC 9110; it sees the site's name and the amount of data, not the content. A VPN is no different: it hides HTTP traffic from the café's Wi-Fi, not from the path beyond the VPN server.
Proxynet's gateway relays HTTPS tunnels without decrypting them, so you install no certificate from us when you use an HTTPS Proxy in a browser, and HTTPS pages stay encrypted from your browser to the site.
Site owners can use a proxy to check the move to HTTPS from outside: a Residential Proxy opens your site through a home connection in another country, so you can confirm that visitors there get the redirect.
Common mistakes
- Turning "Always use secure connections" off because of one site. Use Continue to site for that site instead.
- Typing a password after continuing. The page is still unencrypted.
- Treating it like a certificate error. Changing the clock or pausing antivirus does nothing for an HTTP site.
- Assuming a VPN or proxy makes an HTTP page safe. It only changes who can read it.
Decision guide
| Situation | What to do |
|---|---|
| Reading an old page on your home network | Continue to site |
| The page asks for a password, card or personal data | Go back; use the app or contact the organisation |
| Café, hotel or airport Wi-Fi | Visit later from a trusted network |
| "You usually connect to this site securely…" | Go back; try another network |
| Your own router or printer page at home | Continue; it is your device |
| The site is yours | Certificate, 301 redirect, mixed content, then HSTS |
Frequently asked questions
Why does Chrome say "Connection is not secure" on a site that opened fine yesterday?
The site has not changed. Your Chrome now has Always use secure connections on, because Google's gradual rollout reached you or because you or your organisation switched it on.
How do I stop the warning for one site?
Press Continue to site. Chrome remembers the choice for that site, which is safer than switching the setting off for the whole web.
Is it safe to enter a password on a "Not secure" page?
No. On plain HTTP the password travels as readable text that anyone on the network path can copy. If you have already typed one there, change it, along with every account that uses the same password.
Does "Not secure" mean the site is a scam or has been hacked?
No. It only says the connection is unencrypted, and many old but honest sites never moved to HTTPS. A scam site can just as easily have HTTPS, so the padlock is not proof of honesty either.
Why do I see it on my phone?
Chrome on Android, iPhone and iPad has the same setting under More > Settings > Privacy and security and shows the same warning when it is on. Phones join public Wi-Fi often, so the network matters even more there.
Can I turn the warning off completely?
Chrome lets you switch the setting off, but then you lose the warning on every HTTP site, including a fake one that copies a site you trust. Leave it on and continue per site.
Summary
"Connection is not secure" means the page uses plain HTTP, so the network between you and the site can read and change it. With Chrome 154 the warning before public HTTP sites becomes the default; private addresses such as your router stay out of it. Continue to read pages on a trusted network, never to log in or pay, and keep the setting on. If the site is yours, move it to HTTPS and add HSTS last. To see which proxy type fits a work task, our proxy page compares them.




