> TLS is not an end goal in itselfCorrect. Can you point out on the dolly where I said otherwise?
> The only even remotely reasonable threat … But aside from that?
You either didn't read what I said properly, or are deliberately misreading it.
I didn't suggest using TLS properly in dev was for specific threat protection in dev environments, but for stopping dumbed down things in dev accidentally getting out into prod, and that it is “practise for best practice in production”.
Unless of course someone has (or thinks they have!) reason to breach commonly accepted good practise and have real data in dev, in which case dev is a de-facto production environment from a security standpoint.
> "best practice" (whatever that term actually means)
It is a well understood term. I'll not spend my time explaining it as you'll easily find that information elsewhere if you care to.