Charming bug in the GeoTrust TrustWatch IE toolbar

I’ve been spending a lot of time working with various client-side anti-phishing products, including GeoTrust’s TrustWatch. Turns out it appears to have a fairly serious bug: if you go to an unverified site (which should show a yellow icon), then visit a verified site, the toolbar icon won’t update– so the known-good site still shows as untrusted! If you click the toolbar icon itself, the detailed site report is correct. However, this problem a) makes it hard for me to have a lot of confidence in TrustWatch’s services and b) is certainly misleading, since it makes good sites appear to be bad.

Update: not only is this a bug, it’s inconsistent. Sometimes refreshing the page fixes it, but not always. Sometimes moving through the page history fixes it, but not always. There’s also a case that looks like a bug but isn’t: when page A (which shows up as unverified) redirects to page B (which is verified), the icon will change.

Comments Off on Charming bug in the GeoTrust TrustWatch IE toolbar

Filed under Security

Comments are closed.