This is how many office PCs find their file servers. People are not going to give up the habit of using single label names on the LAN just so ICANN can start collecting rent on that namespace.
http://www.iab.org/documents/correspondence-reports-document...
Slight nitpick: they were prohibited only without prior ICANN approval (second whereas). Companies like Google attempted to get that approval (Google wanted "search"), which spurred ICANN into making a decision about what circumstances they would allow them. This decision essentially states ICANN won't approve any dotless domains.
If I added an A record for google.com to bing.com's ip address on my internal dns no one would see google.com
User takes laptop home and forgets to enable the company VPN.
Additionally, this informational Network Working Group draft has information on the status of existing dotless domains, without expressing an opinion on security or stability[1]
[0] - http://www.icann.org/en/news/public-comment/sac053-dotless-d...
[1] - http://tools.ietf.org/html/draft-hoffine-already-dotless-02
Anyhow, our research and testing (I am one of authors of one of the studies mentioned in the posted article) found that the issues found with SAC 053 have the potential to be much more wide spread. There is also a scary problem called universal XSS.
There were no real smoking gun security issues, so you can make a pretty decent argument about the security impact not being too great (we had many such debates internally), but we are talking a core Internet system. The namespace collision issue is huge.
As for the universal XSS, this can be solved at the browser and page level. First the gTLD as any other level should be explicitly declared in the script URL from the open page and second the browser blocks all the rest.