That is not true in several ways. Iframes and cdns work. There are security measures that prevent https connections from embedding http and other content restrictions, but those are for security reasons. People hotlink images, it's a wild web out there
For everything you described there is a tag or http header i can set on my own content to prevent a browser on another domain from 'hotlinking'. If you are the 'browser' as this IOS feature is, there is none. I hope it at least respect the robots.txt rules.