Automatically avoiding mixed-content warnings when using SSL
digital.bigfish.co.uk
digital.bigfish.co.uk
It's a generally interesting point though, that feeds into questions of what the general purpose of SSL is. This still has benefits for the end user — the café owner/hotel company/etc. can't modify their connection — and so surely is better than nothing, but is it enough?
IMO, if you haven't vetted it, don't pawn it off as secure.
I realize their are practical limitations, but simply turning oneself into a blind indirection does not meet a particularly high standard, again IMO.
And the other commentor has a point about MITM, even if you decide you trust the image source.