[Merge M-56] Display "Not secure" verbose state for data: URLs

data: URLs don't define a secure context, and are a vector for spoofing.
Display a "Not secure" badge for all data URLs, regardless of whether
they show a password or credit card field.

BUG=684811
TBR=estark
NOTRY=true
NOPRESUBMIT=true

Review-Url: https://codereview.chromium.org/2648353005
Cr-Commit-Position: refs/heads/master@{#446536}
(cherry picked from commit effd1d519ff74fb1eb998e844f19d5079222b0fd)

Review-Url: https://codereview.chromium.org/2666783006
Cr-Commit-Position: refs/branch-heads/2924@{#892}
Cr-Branched-From: 3a87aecc31cd1ffe751dd72c04e5a96a1fc8108a-refs/heads/master@{#433059}
4 files changed