The HTTPS protocol works nearly the same as the old HTTP but it is + S (Secure). Data being sent over the HTTPS ports are being encrypted, so that no external 'watcher' is able to read the content that goes through our cables. For images this is not 100% true but it is for a few other reasons recommended to use it for them too.
You may have noticed that for most today's sites there is a green lock in the address bar of your browser:
(Firefox example)
If I would load an image on SteemWorld that does not come from an HTTPS domain the green lock would change to a yellow or red one and by clicking on it there would show up a hint stating 'This page is not secure'. To avoid this I'm filtering non-HTTPS sources on the page.
Many people copied the link to their profile picture (pointing to an old HTTP source) into the Public Profile Settings on Steemit. Here is how it should look like (example from my profile):