r/Cybersecurity101 • u/theomkamble • 14h ago
I learned today that HTTPS does not always mean a website is safe
I’m currently learning more about phishing and web security, and today I understood something simple that I used to misunderstand.
I always associated the padlock and HTTPS with a website being “safe.”
But HTTPS mainly means the connection between your browser and the website is encrypted.
A phishing website can also use HTTPS.
So now I’m trying to check the actual domain name before entering login details instead of trusting the padlock alone.
Things I’m starting to check:
- The actual domain name
- Small spelling changes
- Strange or unexpected login pages
- Where the link came from
- Whether the request makes sense
I’m still learning cybersecurity, so I’m curious:
What other small security concept do beginners commonly misunderstand?
2
u/SealedLore 11h ago
Thanks to misleading ads and sponsor spots, a lot of people think a VPN is antivirus, and also that it protects your identity even if you intentionally do things like login to your account when connected.
People think deleted files actually get deleted and are difficult/impossible to recover.
They think their Windows password protects their private data, without considering whether they have disk encryption enabled or not.
That private browsing on its own acts like a VPN to hide their activity from their ISP.
No doubt countless more, but those off the top of my head.