Great work misha, but this is a security/privacy vulnerability! I just tested by hooking my display picture to one of my servers, and I can see everyones IP addresses and user agents being leaked!
it exposes IP addresses, user agents, and even tells me what article they viewed! I can effectively use my avatar to get a list of all IP's who view different articles, and with some pattern/location analysis, I may even be able to identify who that IP belongs to.
It also gives me the potential to send malicious images to all GOLOS users if there is ever an exploit in browser image handling (it happens sometimes)