- Using HTTPS directly, in particular with HSTS set (optimal).
- Use a third party like CloudFlare to add HTTPS via their proxy.
- Alternatively: HTTP with Content Security Policy set (since it will reject their scripts and CSS running as it isn't in the whitelist). This is only a short term solution since they can alter the CSP header, but it will work if you're stuck on HTTP for now. We bounce a lot of advertisers and malware off of our site this way.
Ultimately this is yet another "Use HTTPS!" broken record. But the CSP solution works until they get wise to it.