Am I misunderstanding something, or wouldn't this just be solved if they simply used SSL for all communications?
The issue is mainly got to do with third party apps + this flaw in Peach's API. There is already one[0] which has reversed the Peach API, and the flaw is still present. What happens when another third-party Peach app comes out and does not use SSL, you can still use Peach's API without SSL and it does not default to HTTPS.
This sort of flaw would lead to a similar issue to the Snapsaved leak[1].
[0] http://techcrunch.com/2016/01/14/peach-gets-an-unofficial-we...
[1] http://techcrunch.com/2014/10/13/snapsaved-takes-responsibil...