“Your Connection Is Not Private” on iPhone
What an HTTPS certificate warning actually means on iPhone, which kinds are dangerous, and why the safe answer is almost never to tap through.
Updated August 2026
Quick answer
It means your browser could not verify that the site is who it claims to be — so anything you type could be read or altered in transit. The three common causes are an expired certificate, a self-signed one, and a name mismatch (the certificate belongs to a different domain). On a public network, or on any site where you would enter a password or card number, treat it as a stop sign rather than a warning: leave and reach the site another way.
What the warning actually means
HTTPS does two separate jobs. It encrypts the connection, and it proves the server on the other end really controls the domain in the address bar. A certificate warning means the second job failed. Encryption may still be happening — but encrypting a conversation with a stranger who is impersonating your bank is not much comfort.
This is why “it's just a warning, the padlock is only for shopping sites” is bad advice. The padlock is about identity, and identity is exactly what is in question.
The four causes, and how worried to be
| What went wrong | Typical innocent cause | Real risk |
|---|---|---|
| Expired | Someone forgot to renew — extremely common on small or internal sites | Low on its own, but you cannot tell an expired certificate from a stolen one by looking |
| Self-signed | A router login page, a home NAS, a dev server | Fine on hardware you own; on a public website it is a strong warning sign |
| Name mismatch | Site served from the wrong hostname, or a stale redirect | High — this is what an interception attack looks like |
| Untrusted issuer | A corporate or school network inspecting traffic | High outside that context — it means something is sitting between you and the site |
Bear in mind the innocent explanation and the attack look identical from the outside. That is the whole problem: the warning exists precisely because your device cannot tell them apart.
What to do when you see one
- 1
Do not enter anything
No passwords, card numbers, or personal details — not even on the page after the warning.
- 2
Check the address bar carefully
A certificate error alongside a slightly-off domain name is a much worse sign than either alone.
- 3
Leave the network out of the equation
If you are on café or hotel Wi-Fi, switch to cellular and try again. If the warning disappears, the network was the problem — which is itself worth knowing.
- 4
Reach the site another way
Type the address yourself, or use the company's app. Do not follow the link that produced the warning.
- 5
Only proceed on hardware you own
Your own router's admin page will legitimately be self-signed. A bank never will be.
How Avodek handles it
Avodek checks each page you open and warns before loading a site whose certificate is expired, self-signed, or otherwise invalid. It names which of those went wrong, rather than showing one generic message.
The deliberate difference: certificate problems cannot be bypassed. There is no “proceed anyway” link — the only option takes you back. That is a stricter stance than most browsers take, and it is a considered trade-off: the times a person taps through a certificate warning correctly are vastly outnumbered by the times they should not have.
Avodek also upgrades over 1,000 major sites to HTTPS automatically, so a downgrade to plain HTTP is caught rather than quietly accepted.
Common questions
Is it safe to continue if I trust the site?
Trusting the site is not the question — the warning means your device cannot confirm you are talking to that site at all. Someone intercepting the connection would produce exactly this warning on a domain you trust.
Why does it only happen on some networks?
Because some networks inspect or redirect traffic. Captive portals on hotel and airport Wi-Fi commonly trigger it before you sign in; corporate and school networks may install their own inspecting certificate. If switching to cellular clears it, the network was intercepting.
Can an expired certificate really be dangerous?
The expiry itself is usually just neglect. The danger is that expiry disables the check that would otherwise catch a stolen or forged certificate, so you lose the guarantee at the exact moment you would want it.
Why won't Avodek let me continue anyway?
By design. Phishing and interception attacks rely on people tapping through, so Avodek removes the option for certificate failures rather than making it slightly inconvenient.
Related guides
Get Avodek
Private Browser + AI · Free on the App Store.