When viewing this thread..http://forum.bitcoin.org/index.php?topic=21052.0;topicseen
..I got an HTTP login prompt, apparently because the page was trying to display this image from someone's profile..http://pool.bloodys.com/?action-userbar&cmd=2a8ca8960d59854f4e04b1963161b766.png
An unsophisticated user might enter their forum.bitcoin.org credentials into that prompt.
More generally, loading offsite images is an information leak (IP addresses of forum readers) and possibly even security risk (if any browser image-handling flaw would let the source site do more, such as redirect to some other site's
flaw, run JS, or in a worst-case, buffer-overflow for local code execution).
I suggest in our new security-conscious era, loading of offsite images as profile icons be disabled.