This seems like pure laziness. Did the developers really not have an understanding of basic PKI? Or did they realize late in the game that their local web socket was gonna require HTTPS and slap this on at the last minute?
Do we know about a one B2C company who lost the business due the security breaches in their products?