1) All Sudoroom services should use HTTPS2) all HTTP sites should redirect to HTTPS3) HTTP Strict Transport Security headers should be set see e.g. www.noisebridge.net www.eff.org etc. --mark B.