> You can try an Ajax request or loading a picture over SSL and then redirect with JS if it doesn't fail.
Neat idea, but wouldn't this still be exposed to ISP-level attacks? Since the user is still loading the page initially in plain HTTP, so the ISP could still inject code, remove the JS redirect, etc.