Journal · Engineering

In October, Chrome will warn people before opening some websites

In October 2026, Chrome 154 will show a full-page warning before opening any public website with no HTTPS. Sites that already have a certificate get upgraded quietly and see no change at all.

In October, Chrome will warn people before opening

A small engine repair shop in Brownsburg has had the same website since 2012. It loads, the hours are right, the phone number works. In October, Chrome will put a full-page warning in front of it.

Your site is almost certainly not that site.

Google's own measurements put HTTPS at 95 to 99 percent of all Chrome page loads, and at 97 to 99 percent once you set aside private addresses like office intranets and routers. If you are in that 97 percent, October changes nothing for you. I am putting that in the third paragraph instead of the last one, because you are going to get emails about this in September and most of them will be selling you something.

What Chrome is actually doing

Chrome's security team announced on October 28, 2025 that a setting called "Always Use Secure Connections" would become the default. One group already has it. Chrome 147 shipped in April 2026 and turned the setting on for everyone enrolled in Enhanced Safe Browsing, which Google counts at over a billion people. Chrome 154, expected in October 2026, turns it on for everybody else.

The mechanism matters more than the headline.

When someone types a bare address or clicks an old http:// link to your shop, Chrome does not load that link as written. Chrome tries the https:// version first. If the secure version answers, that is the page they get, and they see nothing unusual at all. The warning appears only when the secure attempt fails, which means your domain has no working certificate.

Chrome only shows the warning when the secure version of your site fails to answer. That is the whole test.

Google's pilot data backs up how narrow this is. The median user in the test saw fewer than one warning per week. The user at the 95th percentile saw fewer than three. Private addresses are exempt, so the tablet in your back office that talks to a router at 192.168.1.1 is not going to start throwing screens at your staff.

This is the same direction Google has been walking for a while, and it rhymes with dropping passwords for passkeys back in July. Google tightens a default, announces it a year ahead, and the shops that get hurt are the ones nobody told.

Will my site show the warning?

Sixty seconds, on whatever device you are holding.

Open Chrome. Type your web address with https:// in front of it, so https://yourshop.com, and press enter. Do not type the bare name and let the browser guess.

If the page loads and there is a padlock or a small tune icon to the left of the address, you are finished. October does not touch you.

If you get a screen saying your connection is not private, or the page will not load at all, you are in the 3 percent and you have about eight weeks.

Run it twice, once for https://yourshop.com and once for https://www.yourshop.com. A certificate can cover one and not the other, and customers type both. It is a narrower version of the fifteen-minute check I wrote up earlier this week, aimed at one specific thing.

What does it cost to fix?

Usually nothing.

Certificates ran $60 to $200 a year until Let's Encrypt, a nonprofit certificate authority, started issuing them free in 2016. Now almost every host hands one out on request. On Squarespace, Wix, Shopify, and Square Online it is already on and you cannot switch it off. On GoDaddy, Bluehost, HostGator, and most cPanel hosts it is a toggle in the dashboard labeled SSL.

If you cannot find the toggle, the email to your host is two sentences:

My site is still serving over HTTP. Please enable the free SSL certificate and force HTTPS redirects on yourshop.com and www.yourshop.com.

Any host worth paying does that inside a day. If yours cannot manage it in a week, you have learned something useful about your host. Send us the domain through our contact page and we will tell you what is actually wrong with it, no charge.

The part that catches shops who think they are covered

Your main domain is one address. Most shops have more than one.

The booking page on a separate subdomain. menu.yourshop.com. order.yourshop.com. A scheduling host your salon software set up in 2019 that nobody has logged into since. A certificate covering yourshop.com and www.yourshop.com does not cover menu.yourshop.com. They are separate to a browser.

Then there is everything you printed. If the QR code on your counter, the decal on your window, or the back of your business card encodes http://menu.yourshop.com, and that host has no certificate, a customer standing six feet from you gets a warning screen instead of your menu. That one is worth checking before October, because reprinting takes longer than installing a certificate.

What you can ignore

In September, somebody will email you about a Google deadline and a security penalty, and offer you an SSL protection package for $199 a year or a monthly plan that bundles it with things you already pay for.

Certificates are free and they renew themselves on every host worth using. There is no new ranking penalty here either. Google has treated HTTPS as a ranking signal since 2014, and it called the signal lightweight at the time. Nothing about that changes in October.

You can also ignore the advice to hunt down every old http:// link pointing at your site from directories and other people's pages. Chrome upgrades those on its own. Fix the certificate and the links stop mattering, the same way the AMP plugin sitting on your site doing nothing stopped mattering once the standard behind it went away.

The Brownsburg shop will be fine too, as soon as somebody logs into its hosting account. Working out who has that password is going to take longer than installing the certificate. It usually does.


Sources

# Source What it backed up
1 HTTPS by default Chrome 147 in April 2026 and Chrome 154 in October 2026, the 95 to 99 percent and 97 to 99 percent adoption figures, and the warning-frequency pilot data.
2 Ask-before-HTTP adoption guide That Chrome attempts HTTPS first and only warns when the upgrade fails, plus the private and single-label host exemptions.
3 Chrome to warn users before loading HTTP sites The October 28, 2025 announcement date and the Enhanced Safe Browsing rollout to roughly one billion users.
4 Let's Encrypt Free automated certificates from a nonprofit certificate authority since 2016.
5 HTTPS as a ranking signal Google has counted HTTPS as a lightweight ranking signal since 2014.

Luminest builds websites for small businesses from $100/mo and custom software from $12k. Book a free 30-minute call.