There's genuinely no excuse for Flurry (or any other vendor) to have an API that is not secured with HTTPS by default. I can't think of any reason other than stupidity or laziness, and those aren't excuses.
This is especially true of Flurry, which is tailored for connections directly from devices.