Submitted by war59312 on Sun, 08/28/2016 - 11:18
Hi,
Please upgrade the security a bit more.
Should use Upgrade Insecure Requests @ https://www.w3.org/TR/upgrade-insecure-requests/
Should enable HPKP (HTTP Public Key Pinning) @ https://report-uri.io/home/pkp_hash
Should use CSP (Content Security Policy) @ https://report-uri.io/home/generate
And other security headers @ https://bitcoinsecurityproject.org/WebApplicationSecurityPractices/Secur...
Thanks,
Will