It doesn't hold up to SSL stripping very well. As we are working under the assumption of a compromised host, the absence of a signature on the Trezor when you don't expect one wouldn't raise any suspicion. The omnipotent host malware can remove all references to the payment request being signed from the payment gateway before the user sees it.