Besides that, I don't quite understand what separates this from any other IM platform..?
Besides that, I don't quite understand what separates this from any other IM platform..?
It is important to understand that albeit it's not proper https, this is still an encrypted connection that will make eavesdropping impossible. Being signed by an actual authority is only necessary to ensure the website we're talking to is actually secure.grepular.com, and not a man-in-the-middle that would intercept our queries and forge answers. "Unfortunately", both ideas of security and authentication are part of https, and having one without the other is going to pop big scary messages.
This sort of https is still more secure than plain http.
His point about transmitting the password in plain sight is a very good one. Firesheep showed how bad it is to transmit your cookies in plaintext, but sending your login/pass is even worse.
Invalidly signed HTTPS is only slightly more secure than HTTP. Let's look at the open WiFi scenario. If you login to ServiceX over HTTPS but ignore certificate warnings, I can just mount a man-in-the-middle attack and relay all your traffic to ServiceX. It's more involved than just sniffing your cookies, but its still quite practical.
The only place where ignoring certificates is OK is if you know that an attacker can _read_ your network, but cannot write anything to it.
In the case of someone attacking you on WiFi, that self-signed certificate wasn't issued by the site owner. It was issued by the attacker. If you happily ignore warnings, your browser will just setup a "secure" connection to the attacker. Then the attacker just creates another HTTPS connection to your actual destination, and proxies the content back and forth.
Now, if the attacker can only read packets, then yes, the actual encryption is still secure. But in many places where an attacker can sniff (WiFi, on your Ethernet), they can also inject.
There are lots of problems with CAs and the crappy verification that goes into most certificates. But having a CA cert for SSL still significantly raises the bar and limits the extent of an attack. (If one did get a signed cert for PayPal or Facebook, they couldn't just go and publish it in a program like Firesheep, as it'd get revoked pretty quickly.)
If it's a self signed certificate, how can you tell between a certificate self signed by the website owner and a certificate self signed by the eavesdropper?
If this guy wants to use SSL he should do it properly.
If you want to install cacert.org's root certificate in your browser, visit here: https://www.cacert.org/index.php?id=3
Kik.com has over a million users transmitting login credentials and private conversations. secure.grepular.com doesn't.
See https://cacert.org/ and install their root if you think the CA model is broken and should be free.
"Besides that, I don't quite understand what separates this from any other IM platform..?"
GTalk, MSN, Yahoo Messenger, AIM, ICQ and Skype all encrypt your login details. Kik doesn't
GTalk, ICQ and Skype all encrypt your actual conversations. Kik doesn't.
All of the above mentioned IM services have publicly stated that they don't log IM conversations. Kik hasn't.