* X-FRAME-OPTIONS I feel like the number of times this has prevented a useful action vs prevented a bad action is many:0
* X-CONTENT-TYPE-OPTIONS So, instead of browsers actually honoring the Content-Type header, we have to ask with a "pretty please"?
* STRICT-TRANSPORT-SECURITY Doesn't prevent problems on a first connect, but definitely a good idea (if your site supports SSL that is:)). Blanket TLS is a good thing.
Just my 2¢