
It's not much of a Band-Aid, but is there a way to—or could NoScript be enhanced to—force some of the Big Web Farm content to HTTPS only if the embedding site is HTTPS-"secured"?
Best possible example: HTTPS Twitter includes HTTP twimg.com content; if I just force HTTPS for twimg.com, some other websites / webapps break.
Once again, relying on NoScript to fix brain-dead websites when the operators just close support tickets without answering them...
PS: Silly regex question: what's the best way to create a single-line expression for "all http://site.com/.* OR http://subdomain.site.com/.* content?