Storming Solutions

Digital Hub / Web Development

What Is SSL (and the Padlock)?

Updated 17 August 2026

Jump to section

SSL is the technology that encrypts data traveling between a visitor's browser and your website, so passwords and payment details cannot be read in transit. It is what turns http:// into the secure https:// and once put a padlock in the address bar. The protocol in use today is really its successor, TLS, though the certificate is still called an SSL certificate. Google has treated HTTPS as a lightweight ranking signal since 2014, so every site needs one.

What does an SSL certificate do?

An SSL certificate does two jobs at once. It encrypts the connection, so anything sent between browser and server is scrambled to anyone listening in between.

It also proves the site is served by the domain it claims to be. The certificate is issued for your specific domain by a trusted authority that checks you control it before signing.

A browser reads that signature and confirms the connection is both private and going where it should.

The result is HTTPS, the secure version of the web's transfer protocol. Without a valid certificate, a modern browser cannot establish HTTPS and warns the visitor instead.

What happened to the padlock?

The padlock is mostly gone. For years browsers showed a padlock icon next to secure sites.

People misread it as proof the site was safe or legitimate, when it only ever meant the connection was encrypted. Because scam sites can also get free certificates, the padlock was giving false reassurance.

Chrome replaced it with a neutral settings icon in late 2023, and other browsers followed.

The signal that matters now is the reverse one. A site served over plain http, with no certificate, shows a clear "Not secure" warning.

That warning is what scares visitors away. So the job today is simply to hold a valid certificate and avoid it.

Do you need SSL, and what does it cost?

Every site needs SSL, including a plain brochure site with no login or payment form. Browsers flag any http page as not secure, Google favors HTTPS, and visitors have learned to distrust the warning.

There is no site small enough to skip it.

The good news is that it is usually free. Let's Encrypt, a nonprofit certificate authority, issues certificates at no cost and renews them automatically.

Most hosting plans include this by default, so you should not be charged separately for a basic certificate.

There are paid certificates, but most sites do not need them. They mainly differ in how much the authority verifies before issuing.

Type What it verifies Typical use
Domain Validation You control the domain Almost every business site
Organization Validation The domain and the organization Larger companies wanting extra assurance
Extended Validation A stricter legal check of the business Banks and high-trust sectors

Frequently asked questions

Is an SSL certificate free?

Usually, yes. Let's Encrypt issues free certificates that renew automatically, and most hosting plans include SSL at no extra charge. You only pay when you choose an Organization or Extended Validation certificate for extra assurance. If a host tries to bill you for a basic certificate on top of the plan, that is worth questioning against the other running costs of a website.

Does my site need SSL if it has no login or payments?

Yes. Even a simple brochure site needs SSL today. Browsers mark any http page as "Not secure", which visitors notice and distrust, and Google prefers HTTPS pages. A contact form alone sends data you should protect. There is no practical reason to run a modern site without a certificate.

What does "Not secure" in the address bar mean?

It means the page is loading over plain http with no valid certificate, so the connection is not encrypted. Anyone on the same network could read what is sent. It can also appear if a certificate has expired or is set up wrong. The fix is to install or renew a valid certificate and serve the whole site over HTTPS.

What is the difference between SSL and TLS?

They are two generations of the same idea. SSL is the original protocol, now retired for security reasons, and TLS is its modern replacement that actually runs today. The industry kept saying "SSL" out of habit, so "SSL certificate" and "TLS certificate" mean the same thing in normal use. What matters is that the certificate is current.

What happens when an SSL certificate expires?

The site keeps running, but browsers stop trusting it and throw a full-page warning that most visitors will not click past. Certificates have a fixed lifespan and must be renewed, which is why automatic renewal matters. In our experience, on sites handed over with no maintenance plan, a lapsed certificate is exactly the kind of basic that slips first. It often surfaces alongside the causes in why a website is slow.

Keeping your site trusted

Storming Solutions builds and maintains websites for Malaysian businesses, and a valid certificate with automatic renewal is part of the baseline we set up, not an upsell. We would rather it never lapse than sell you a fix after a browser warning has already turned visitors away.

If your site shows "Not secure", or you are unsure whether renewal is handled, message us on WhatsApp. Then talk to us about web development, where we set the security basics up as part of a build, with hosting and renewals on the table from the start.

WhatsAppCall 011-2333 6888