Comment by swiftcoder
10 hours ago
> runtimeterror.com has no https which is available for free, so I'm not entering it
I think your threat model needs some work here. What exactly does https guard against when downloading a jpeg? A intermediary swapping it out for a different jpeg?
Downloading things from an unknown domain over https still carries the risk of the site itself vending you malware...
Perhaps a compromised device on the local network can MiTM a javascript payload that exploits three zero days on HackerThemAll's browser stack, pwning his computer and finally enabling his super advanced, persistent adversaries to get exfiltrate his super important data.
And all that for what, for a VB6 screenshot on a hn comment threat while procrastinating on top secret work ?
Nah, not worth it.