Public Secret bug reports.

Team Bounty Title
Secret - Broken Authentication and Session Management
Secret - ClientId gives away platform (iOS/Android) from which a secret was posted.
Secret - secret app for iOS and android is sending some info over HTTP
Secret - Content Sniffing not disabled
Secret - Login CSRF in Secret.ly
Secret - Strict Transport Security on secret.ly
Secret - SSL Not Enforced