> By that logic, we shouldn't bother securing wifi APs because everything's encrypted at the application layer anyways.
Sure. Why not? I do banking and I read my email on public, untrusted networks like airport and hotel wifi, Starbucks and the internet.
I see not problem with that.