It is security by obscurity. At least the user cannot share a link to the image. I have not done this yet, but these 2 articles should link together nicely and provide a solutions. I will update once it is complete.
http://www.dotnetcurry.com/showarticle.aspx?ID=129&AspxAutoDetectCookieSupport=1
http://www.dotnetperls.com/file (the ReadAllBytes section)