Visit https://ianfette.org, open the security panel. Observe that it says "This page is insecure (broken HTTPS)."
This is on both the interstitial and after you click through.
To fix this, I think we might want to add a "main_explanation" or some such to content::SecurityStyleExplanations, and have DevTools display the main_explanation string instead of making it up itself. Then, for malware/phishing pages, we could send "This page is valid HTTPS but has malware or phishing" instead of "This page is insecure (broken HTTPS)".
This would also be helpful for bugs like issue 543864, where we might want to display a different "main explanation" for chrome:// or other non-https secure origins than we do for https.
Comment 1 by vakh@chromium.org
, Oct 21 2016