Yay ??? I can simply call an ???https://??? location in an image I embed on a website and the action is performed regardless whether the page was sniffed or not. (For sake of argument we???ll ignore that some browsers warn when secured and non-secured content is mixed.)