Looks like when HTTP remote can't return an object and returns access denied we consider it the same way as 404 and don't even mention this to user.