TLS encrypts a connection, not endpoint intentions
A padlock tells you the conversation is private. It says nothing about who you are having it with.
Certificates are free and instant, so a phishing site has one within minutes of registering its domain. Advice built on "check for the padlock" made sense when certificates were slow and expensive, and is now close to useless as a safety signal. The padlock means nobody in the middle is listening, which is not the same as the other end deserving your password.
More on TLS and PKI
- Certificates bind keys to names through trust chainsHeld together by a chain of seals
- Certificate expiry creates operational pressureEvery one of them runs out
- Private-key compromise survives a valid certificateThe certificate is fine
- HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit tooThe turning that stops existing
- OCSP stapling moves status evidence closerThe proof comes stapled on
- Mutual TLS authenticates both endsBoth of you show papers
