Nitpicking. Let me reflect - runtimeterror.com has no https which is available for free, so I'm not entering it.
Nitpicking. Let me reflect - runtimeterror.com has no https which is available for free, so I'm not entering it.
It is a direct image link, it wont ask your password.
Also, https is not available for free even if some solutions are available without asking money for it. In this case: the site is on a shared host so the only option is the paid one from the host (so it isn't free-as-in-money) while the alternative is having a VPS and installing something like let's encrypt (which is more expensive than the shared host and requires me to play sysadmin for it, so not only it isn't free-as-in-money but also free-as-in-time).
Have you lived under a stone? No wonder we have so many vulnerabilities if people have no idea about images being malicious, exploiting image decoding libraries.
I think your threat model needs some work here. What exactly does https guard against when downloading a jpeg? A intermediary swapping it out for a different jpeg?
Downloading things from an unknown domain over https still carries the risk of the site itself vending you malware...
And all that for what, for a VB6 screenshot on a hn comment threat while procrastinating on top secret work ?
Nah, not worth it.