No need; the browser will block http:// included from https:// pages. Including from a http:// page? Then a compromised jquery cdn is the least of your worries.
In short; no, just a compromised dns record is not enough.
Data export is definitely on the horizon. Password protection is on the list, but not yet definite. We actually do support multiple currencies (we hope our users agree it is done in an elegant fashion, feedback welcome) - let us know if we are missing yours and we will get it in the next release.