The lock symbol is broken right now on any page where requests are made for attachments, or images with http instead of https. So if an https page includes a call for http... it's not secure. Makes sense.
I just add this running commentary in case this is interesting for folks
|