It is important to understand that albeit it's not proper https, this is still an encrypted connection that will make eavesdropping impossible. Being signed by an actual authority is only necessary to ensure the website we're talking to is actually secure.grepular.com, and not a man-in-the-middle that would intercept our queries and forge answers. "Unfortunately", both ideas of security and authentication are part of https, and having one without the other is going to pop big scary messages.
This sort of https is still more secure than plain http.
His point about transmitting the password in plain sight is a very good one. Firesheep showed how bad it is to transmit your cookies in plaintext, but sending your login/pass is even worse.