We are currently working on a non flash websocket version of webchat. https://github.com/net-bits-net/as2js
What about also getting an SSL certificate from an Authority? People start seeing "Not a secure connection" or some nonsense when HTTP is used and its going to startle. As well passwords should be sent over SSL/TLS.