> strict-transport-security:max-age=10886400; includeSubdomains
This sensational article fails to mention that.
To protect your website visitors, enable the HSTS header on your web server. Basically just use SSL Labs[2] and fix everything until you have an A+ rating.
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
[2] https://www.ssllabs.com/ssltest/analyze.html?d=wakatime.com