
Six engineers on Google's Chrome Security team published a short post last fall with a date in it. "One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable 'Always Use Secure Connections,'" the team wrote on Google's security blog on October 28, 2025. Chrome will ask the user's permission before the first visit to any public site that does not run on HTTPS. Google published a screenshot of what that looks like. A gray box, a line warning that attackers could view or change what gets sent, and a choice: continue to the site, or return.
For most of the internet this is housekeeping. Certificates are free and automatic now, and the large platforms handled it years ago. For a propane retailer whose site was stood up in a rush, paid for once, and never opened again, it is closer to a public notice — the first time in years that anybody will be told, in writing, that there is something wrong with the company's website.
The padlock is only the part that will be visible. Underneath it sits a slower problem the trade rarely discusses, because it produces no invoice, no complaint, and no phone call: a dealer's website ages out of usefulness at a pace nobody is watching. Trucks get inspected. Tanks get inspected. The website gets a renewal notice from a registrar once a year, and that is the whole of its maintenance program.
Originally published on Propane Insider.