Chrome 154: What Is “Always Use Secure Connections” and How to Turn It On on Android?

Chrome 154 changes how Chrome handles HTTP websites. Learn what Always Use Secure Connections means and how to enable it on Android.
Chrome 154 Always Use Secure Connections setting on Android

Chrome 154 brings an important change to the way Chrome handles websites that do not support HTTPS. With Always use secure connections enabled, Chrome tries to use HTTPS first and can warn you before opening a site that does not support a secure connection.

Chrome 154 reached the stable channel on September 22, 2026. Its release notes list “Ask before HTTP on by default” as a privacy and security change. The rollout of the public-sites version of Always use secure connections is gradual.

The practical idea:

Chrome prefers HTTPS. When a public website cannot provide HTTPS but may still work over HTTP, Chrome can ask before continuing over that insecure connection.

In this guide, we explain what Always use secure connections actually does, how Chrome handles an HTTP website, how to find the setting on Android, what the two warning modes mean, and why HTTPS is important without being a guarantee that a website itself is trustworthy.

What Changed in Chrome 154?

The important change is not that HTTP websites have disappeared. Instead, Chrome is making insecure HTTP navigation more visible to users.

Chrome 154 is the release in which Ask before HTTP is enabled by default. Google’s Chrome documentation says the default configuration uses the public-sites-only mode, so Chrome can ask for permission before a user’s first access to a public site that does not support HTTPS.

Most modern websites already use HTTPS, so many everyday pages should continue to open normally. The change mainly affects the cases where Chrome needs to consider continuing over plain HTTP.

Release vs. rollout

Chrome 154 was released on September 22, 2026. The default HTTPS-first warning behavior is being rolled out gradually rather than appearing identically for every user at the same moment.

What Is “Always Use Secure Connections”?

Always use secure connections is a Chrome security setting that tells the browser to prefer HTTPS connections.

HTTPS helps protect information moving between your browser and a website. When HTTPS is available, Chrome can use that secure connection instead of plain HTTP.

When the setting is enabled, the basic process is:

Try HTTPS → HTTPS unavailable → Warn before HTTP

This does not mean that Chrome can magically add HTTPS to an old website. The website still needs to support HTTPS on its server.

Is It the Same as HTTPS-Only Mode?

Chrome’s user-facing Android setting is named Always use secure connections. Chromium and enterprise documentation also use terms such as HTTPS-first or HTTPS-Only Mode when discussing the related browser behavior and policies.

For everyday users, the important point is simple: Chrome tries to keep ordinary web navigation on HTTPS and asks before using HTTP in the situations covered by the feature.

HTTP vs HTTPS: What Is the Difference?

HTTP HTTPS
Uses an unencrypted web connection. Uses an encrypted connection between the browser and site.
Information sent through the connection may be exposed or changed by an attacker who can intercept the traffic. Helps protect information while it travels between your browser and the site.
Chrome can warn before certain HTTP navigations. Usually opens normally when the HTTPS connection is valid.
Should not be treated as an appropriate connection for sensitive information. Preferred for modern websites and sensitive browsing.

Important: HTTPS protects the connection. It does not prove that the website itself is legitimate.

How Chrome Handles an HTTP Website

Chrome’s current Chromium documentation describes the Ask-before-HTTP flow clearly. When a navigation starts from an HTTP URL, Chrome first tries HTTPS. If HTTPS cannot be used but Chrome believes HTTP may work, it can ask the user for permission before opening the page over HTTP.

How the connection decision works
HTTP URL
The user starts a web navigation.
Try HTTPS
Chrome prefers the secure connection first.
HTTPS works?
If yes, the secure connection can continue.
Warn before HTTP
If HTTPS is unavailable, Chrome can ask before continuing over HTTP.

The warning does not simply mean “this website is a scam.” It means Chrome could not establish the secure HTTPS connection it wanted and is giving you a chance to stop before continuing over HTTP.

Chrome warning before opening a website that does not support a secure connection

What We Observed on Android

During our hands-on check on Chrome 153.0.8010.52 on Android 12, an HTTP-only test site produced the message “This site doesn't support a secure connection” with the options Continue to site and Go back.

This is a real Android observation, but it was made on Chrome 153 rather than Chrome 154. Chrome 154’s default Ask-before-HTTP behavior is documented separately by Google and Chromium.

How to Turn On Always Use Secure Connections on Android

The setting is available in Chrome for Android.

Step 1: Open Chrome Settings

Open Chrome and tap the three-dot menu.

Step 2: Open Settings

Tap Settings.

Step 3: Open Privacy and Security

Tap Privacy and security.

Step 4: Find Always Use Secure Connections

Under the Security section, turn on Always use secure connections.

Google’s current Android instructions use this same path: Chrome → Settings → Privacy and security → Security → Always use secure connections.

Chrome Android Security settings with Always Use Secure Connections enabled

For a broader look at practical Android security settings beyond Chrome, see our Android Security Hardening guide. It covers device-level protections that complement browser security.

Which Always Use Secure Connections Option Should You Choose?

Chrome currently provides two warning configurations.

Warns you for insecure public sites

This option warns you about insecure public websites but does not warn you for private sites such as a company’s intranet.

Warns you for insecure public and private sites

This stricter option also warns you about insecure private sites, including private environments such as a company’s intranet.

Option What it covers Typical use
Public sites Warns before insecure public websites. A practical default for ordinary public-web browsing.
Public & private sites Also warns for private/internal sites. Useful when you regularly work with private or internal HTTP sites and want warnings there too.

Public Sites vs Private Sites: Why Does Chrome Separate Them?

Not every HTTP page exists on the public internet. A company intranet, internal development system, router interface, or other local environment can use a private address or internal name.

Google explains that the risk is different for private sites because an attacker generally needs to be on the same local network to interfere with that traffic. That is why the default Chrome configuration focuses on public sites.

Why Chrome separates public and private sites
Public site
Open internet destination

Chrome's default warning focus is on insecure public websites.

Private / internal site
Company or local environment

A company intranet or local service can have a different risk context, so Chrome offers a separate warning mode.

What Does Chrome’s HTTP Warning Mean?

Seeing the warning does not automatically mean the website is malicious. It means the connection is not using HTTPS and Chrome wants you to make a conscious decision before continuing.

A useful way to think about it is:

HTTP + legitimate site
The site may be real, but the connection is not protected by HTTPS.
HTTPS + malicious site
The connection can be encrypted even when the website itself is fraudulent.
HTTPS + legitimate site
The connection has an important security layer, but normal online caution still matters.

Does HTTPS Mean a Website Is Completely Safe?

No.

HTTPS helps protect the connection between your browser and the website. It does not prove that the website owner is honest or that the page is free from phishing, scams, or malicious content.

For example, a phishing page can still have HTTPS. That is why you should check the domain name and context before entering passwords, payment details, recovery codes, or other sensitive information.

One security layer does not equal full website trust
HTTPSProtects the connection while data travels between browser and site.
≠
Website trustStill requires checking the domain, context and legitimacy of the site.

What Should You Do When Chrome Shows the Warning?

1. Check the website address

Look at the domain name and make sure it is the website you intended to visit.

2. Ask whether you really need the page

If the website is unfamiliar and you do not know why it is using HTTP, going back is a sensible choice.

3. Do not enter sensitive information over HTTP

Avoid entering passwords, payment details, recovery codes, or other sensitive information through an insecure HTTP connection.

4. Consider the context

A public website and a private company or local-network page are not necessarily the same situation.

5. Look for an HTTPS version

An old bookmark or outdated link may point to HTTP even when the website now supports HTTPS.

A simple response to an HTTP warning
STEP 1Recognize the site?If the site is unfamiliar, going back is the safer starting point.
STEP 2Need sensitive information?Do not enter passwords, payment details or recovery codes over HTTP.
STEP 3Is an HTTPS version available?Check for the secure version instead of continuing through an insecure connection.
STEP 4Know the contextPublic and private/internal sites can have different practical conditions.

What Chrome 154 Means for Website Owners

Chrome’s change is relevant to website owners too. If a website still relies on HTTP at any point in a navigation path, visitors may encounter the warning before reaching the final page.

Google and Chromium recommend checking websites that are still served over HTTP, including cases where HTTP appears only during redirects.

Website owners should check

  • Does the main domain support HTTPS?
  • Do old HTTP URLs redirect correctly?
  • Are important pages still served directly over HTTP?
  • Do legacy subdomains still depend on HTTP?
  • Do important internal links still point to old HTTP URLs?
  • Does any redirect chain briefly pass through HTTP?

For site owners, the practical goal is straightforward: serve the public website through HTTPS and test old URLs and redirects instead of assuming that a final HTTPS page is enough.

What Happens If You Use an HTTPS URL Directly?

Starting with an explicit HTTPS URL is different from starting with HTTP.

According to Chromium’s current Ask-before-HTTP guidance, if an explicitly requested HTTPS navigation fails, Chrome does not silently fall back to HTTP. Instead, the user sees the normal network error.

The same principle applies when a site has HSTS configured: Chrome does not downgrade that navigation to HTTP.

Does Chrome Remember My Choice?

Yes. Chromium’s current documentation says Chrome remembers a user’s decision for 15 days, and the exception can be renewed when the user revisits that site.

This means someone who regularly uses a particular HTTP site may not see the same warning on every visit.

Can I Turn Off Always Use Secure Connections?

Yes. Chrome allows users to disable the Always use secure connections setting.

Turning the warning off does not make HTTP secure. It only changes how Chrome handles the warning before an insecure connection.

Common Chrome 154 Questions

Is Chrome 154 forcing every website to use HTTPS?

No. Chrome cannot turn an HTTP-only website into an HTTPS website. The change is about how Chrome handles navigation when HTTPS is unavailable.

Does Chrome automatically convert HTTP into HTTPS?

Chrome attempts to load sites over HTTPS when the secure-connections setting is enabled, but the destination website must actually support HTTPS.

What happens when a site does not support HTTPS?

Chrome can show a warning before allowing the user to continue over HTTP.

Is an HTTP website always dangerous?

Not necessarily. HTTP means the connection is not protected by HTTPS. It does not, by itself, prove that the website is malicious.

Should I enter my password on an HTTP website?

Avoid entering passwords or other sensitive information over an insecure HTTP connection.

Is HTTPS enough to trust a website?

No. Verify the website address and consider whether the website itself is legitimate before sharing sensitive information.

Why does Chrome mention public and private sites?

Chrome provides separate warning modes because public websites and private or internal sites have different practical risk conditions.

Chrome 154 Secure Connections: A Simple Checklist

1. Check the URL
Make sure the domain is the one you intended to visit.
2. Prefer HTTPS
Use the secure version whenever it is available.
3. Treat HTTP warnings seriously
Pause before continuing over an insecure connection.
4. Protect sensitive data
Do not enter passwords or payment details over HTTP.
5. Remember the limit of HTTPS
A secure connection does not automatically prove that a website is trustworthy.

Final Takeaway

Chrome 154 makes insecure HTTP navigation more visible by asking for permission before certain HTTP connections.

The Always use secure connections setting works by preferring HTTPS and warning you when a website does not support a secure connection. Chrome provides separate warning modes for public sites and for both public and private sites.

For most everyday browsing, the change should be relatively simple because modern websites already use HTTPS. You may never notice the warning on sites that are configured correctly.

The more important lesson is understanding what the warning actually means:

HTTPS is a security layer for the connection. It is not a guarantee that the website itself is trustworthy.

When Chrome asks whether you want to continue to an HTTP site, take that warning as a reason to pause, check the address, and decide whether you really need to continue.

Sources & Further Reading

These are official documentation and reference sources used to verify the technical behavior described in this guide.

Google Chrome Security — HTTPS by default
Background on Always use secure connections, the public-sites default, private-site considerations, and the motivation for the change.
Google Chrome Security: HTTPS by default

Google Chrome Help — Manage Chrome safety and security
Current Android instructions and the two Always use secure connections configurations.
Chrome Help: Manage safety and secure connections on Android

Chromium — Ask-before-HTTP adoption guide
Detailed behavior, HTTP fallback rules, 15-day remembered decisions, redirects, and website-owner guidance.
Chromium: Ask-before-HTTP adoption guide

Chrome 154 Release Notes
Stable release date and the “Ask before HTTP on by default” privacy/security change.
Chrome 154 release notes

Chrome Help — Check if a site’s connection is secure
Explanation of secure vs. insecure connections and why HTTPS does not replace normal website-checking.
Chrome Help: Check if a site’s connection is secure

Last reviewed: September 2026. Chrome behavior and settings can change as Google rolls out browser updates, so the exact interface may vary by Chrome version, device, and account configuration.

About the author

Ketan Patadiya
Ketan Patadiya is the founder and technology writer behind Tech With Ketan, an independent technology website covering Android, Google apps, AI tools, cybersecurity awareness, tutorials, and practical digital security. He focuses on explaining techn…

Post a Comment