If I understand the context properly of what you are referring to - there's no issue with ecency's image proxy itself. I was talking about restricting CSP to images.hive.blog so that all external content goes through (ideally) a single controlled proxy within one domain that serves UGC. Fewer allowed origins means smaller attack surface if something goes wrong on any of them.
RE: Core dev meeting #78