What "Your Connection Is Not Private" Really Means
Short answer
Chrome cannot verify the site's certificate, so it cannot prove you are talking to the real site. Click Advanced and read the error code: NET::ERR_CERT_DATE_INVALID usually means your device clock is wrong, which you should fix rather than bypass. Never proceed past this warning on any page where you enter a password or payment details — a valid certificate is the only thing proving the site is genuine.
On this page
A full-page warning, a red triangle, and a button that invites you to carry on anyway. The message is vague by design, which is unhelpful, because the underlying problem ranges from “your laptop clock is two days out” to “somebody on this network is reading your traffic”.
What the warning actually says is narrower than it sounds. Chrome checked the site’s certificate, could not verify it, and therefore cannot prove the server on the other end is who it claims to be. Encryption without verified identity is worthless, because you might be encrypting beautifully to an impostor.
The error code tells you which case you have. It is hidden behind Advanced at the bottom of the warning page, and reading it takes five seconds.
Read the code first
| Code | What it means | Usual cause |
|---|---|---|
ERR_CERT_DATE_INVALID |
Certificate is expired or not yet valid | Your clock is wrong, or theirs expired |
ERR_CERT_COMMON_NAME_INVALID |
Certificate is for a different domain | Misconfigured server, or a wrong address |
ERR_CERT_AUTHORITY_INVALID |
Signed by an untrusted authority | Self-signed device, corporate proxy, or interception |
ERR_CERT_REVOKED |
The issuer cancelled this certificate | Treat as serious. Do not proceed |
ERR_CERT_SYMANTEC_LEGACY |
Distrusted historic issuer | A badly neglected site |
One distinction does most of the work: an error on every site points at your device or network, while an error on one site points at that site.
The rule about proceeding
Do not click through this warning on any page where you will type a password, card number, address, or any personal information. That is not a precautionary-principle flourish. The certificate is the only mechanism that proves the page in front of you belongs to the organisation named in the address bar. Without it, a convincing copy of your bank’s login page and your bank’s actual login page are indistinguishable to you and to the browser.
The same applies to downloading anything. An unverified connection can serve you a modified file.
There is a narrow set of cases where proceeding is defensible:
- Your own router or NAS admin page on your home network, which uses a self-signed certificate because it has no public domain.
- A development server on
localhostor a device on your own LAN. - A static page you are reading and will not interact with, where you have already identified the cause as something benign like an expired certificate on a small site.
Everywhere else, close the tab. Being inconvenienced costs you minutes; being wrong about this costs you an account.
Chrome has a deliberate friction feature here: on some warnings there is no
visible proceed button at all, and you have to type thisisunsafe with the
warning page focused. If you find yourself doing that on a site asking for a
login, stop.
If every site shows the warning
Check your clock
Certificates carry a validity window, and the check is performed against your device’s clock. A clock that is wrong by days or years makes every valid certificate in the world look expired or not-yet-valid.
- Windows: Settings → Time & language → Date & time. Turn on Set time automatically, then click Sync now.
- macOS: System Settings → General → Date & Time. Turn on Set time and date automatically.
- Android: Settings → System → Date & time → Set time automatically.
- iPhone: Settings → General → Date & Time → Set Automatically.
Check the time zone and the year as well as the time. A laptop whose CMOS battery has died resets to a date years in the past on every boot, which produces exactly this symptom and recurs after each shutdown.
Public Wi-Fi that has not been joined properly
A café or hotel network that wants you to accept terms intercepts your traffic until you do. When you request an HTTPS site, the portal cannot impersonate it without triggering this warning, so you get a certificate error rather than the sign-in page.
Open a plain HTTP address — http://neverssl.com exists for this purpose — and
the portal appears. The same mechanism causes the more general case covered in
Wi-Fi connected but no internet.
Antivirus HTTPS scanning
Security suites that scan encrypted traffic do so by intercepting it with their own certificate. That is interception with your consent, and it works until the product’s certificate store goes stale or its installation breaks — at which point every site fails.
Look in your security software for a setting named HTTPS scanning, SSL scanning, web shield or encrypted connection scanning, and turn that module off temporarily. If the warnings stop, you have found it. Reinstalling the product usually fixes it properly.
Corporate and school networks
A managed laptop on a corporate network is likely inspecting traffic with an organisational root certificate, legitimately and with the organisation’s knowledge. That normally produces no warning at all, because the root was installed on the device.
You see warnings when the device is not fully enrolled, or when you are on the network with a personal device. Click Advanced and look at the certificate details — if it names your employer or school, that is what you are seeing. It is not something to work around on your own.
If only one site shows the warning
The most likely explanation is dull: their certificate expired. Certificates are typically valid for months rather than years, and renewal is automated on well-run sites and forgotten on badly-run ones.
Two things worth checking before you assume that:
- Read the domain character by character. Phishing sites use lookalike domains, and a certificate error on a site you reached through an email link is a strong signal to close the tab entirely. A real certificate error on a real bank is rare; a fake site that cannot produce a valid certificate is not.
- Try the site on mobile data, on your phone. A different network and a different device. If it is fine there and broken on your Wi-Fi, something on your network is interfering, which is considerably more serious than an expired certificate.
A warning that appears in one browser but not the one beside it points at a certificate store difference rather than at the site, and why a website works in one browser but not another covers how to tell those apart.
If it is genuinely their expired certificate, there is nothing you can do from your side. Waiting is the fix.
What the padlock does and does not prove
Worth correcting, because it is widely misunderstood. A padlock means the connection is encrypted and the certificate matches the domain you typed. That is all.
It does not mean the site is honest, the company is legitimate, or your data is safe once it arrives. Certificates are free and automated, and phishing operations obtain them routinely. The padlock tells you nobody is listening in between; it says nothing about who is listening at the other end.
So the certificate check is necessary and not sufficient — which is exactly why bypassing it on a login page removes the one guarantee you had.
What to expect
A wrong clock explains most all-sites cases and takes thirty seconds to fix. A captive portal explains most public Wi-Fi cases. Antivirus HTTPS scanning explains most of the remainder, and the fix there is a product setting rather than anything in Chrome.
For a single site, an expired certificate is the usual answer and it resolves itself when the owner notices.
The limitation worth stating plainly: Chrome cannot tell you whether a specific certificate failure is an administrative lapse or an attack. It only knows the verification failed. That ambiguity is the whole reason the default advice is to go back rather than to proceed, and it is why the exceptions above are so narrow.