> runtimeterror.com has no https which is available for free, so I'm not entering it
I think your threat model needs some work here. What exactly does https guard against when downloading a jpeg? A intermediary swapping it out for a different jpeg?
Downloading things from an unknown domain over https still carries the risk of the site itself vending you malware...