If SSL is broken, you are - as many people have noticed, screwed. JMAP itself is entirely encryption layer agnostic. It's transport layer agnostic. JMAP over HTTPS is definitely going to be the first layer, but we're looking at websockets with interest as well.
If you were insane, you could do JMAP over XMPP, or JMAP over email. That would be neatly recursive...