I have an ASP.NET website which requires login and uses SSL on all pages to protect the user's credentials and authentication cookie. Say one page has an image element with the following src:
https://mystorageaccount.blob.core.windows.net/mycontainer/myimage.jpg?sv=...
This requests an image file from a private blob container on Azure Storage, using a time-limited Shared Access Signature. I don't particularly want this image to be intercepted. However, is there any point in using HTTPS for this request? Surely a man-in-the-middle could just use the URL themselves within the SAS timescale to receive the image anyway?
I realise that a more secure option would be to fetch the image from storage server-side, and serve it only to authenticated users, but speed is important so I'd like to avoid this. My question is, when the browser requests images from Azure Storage directly, is there any benefit in HTTPS or should I use HTTP instead?