in any case, it still seems good practice to host sensitive images externally so you retain more control and don't have to rely on the shifting (and feasibly changeable, by bad actors) vagaries of mastodon federation rules