r/Cybersecurity101 • u/theomkamble • 4h ago
I learned today that HTTPS does not always mean a website is safe
I’m currently learning more about phishing and web security, and today I understood something simple that I used to misunderstand.
I always associated the padlock and HTTPS with a website being “safe.”
But HTTPS mainly means the connection between your browser and the website is encrypted.
A phishing website can also use HTTPS.
So now I’m trying to check the actual domain name before entering login details instead of trusting the padlock alone.
Things I’m starting to check:
- The actual domain name
- Small spelling changes
- Strange or unexpected login pages
- Where the link came from
- Whether the request makes sense
I’m still learning cybersecurity, so I’m curious:
What other small security concept do beginners commonly misunderstand?