It is much, much easier to redirect all non-www traffic to www if a subdomain is not specified then otherwise and a wildcard or SAN-enabled certificate will make it much more flexible in the future.
In addition, the SSL stuff is irrelevant. You can use "www" under a wildcard cert just as easily as you can "app" or "dashboard", and if you're doing it right you're going to need to setup SSL on both anyways. Why does choosing WWW make it more complicated, and how will a "www" certificate get in the way?
Why? Because you need your domain root to have all sorts of other stuff in it- MX records, SPF keys, and various other things. A lot of CDNs and DNS based tools work really well by utilizing CNAMEs, which you can't do on the root. Putting your website on "www" keeps is as a separate isolated service and makes adding those services easier down the line.
Damn good reason too! I can't think of a good way round it. Do people like CloudFlare configure using CNAMEs? If they do, this strongly weights my decision, (along with the 'non expert users like www.' argument - though I think as long as you use a .com you're probably okay there).
You hit what I was saying spot on. It's not just a matter of CDNs either, there are a lot of services where using CNAMEs become important.
But many non-technical people cannot understand if something is a website URL without the WWW in front of it. It's probably best to add WWW if your target audience is normal humans.
Problem solved.
You can put a canonical meta tag on each page, but as I understand you lose a few percent of the page's value. 301 redirect is the only way to conserve all of the value.
Not an expert, just repeating stuff I've been told by our SEO guys.
From Google's perspective, the problem with 301s is that they take longer to load (since you've got to request two separate URLs) and they make your URL structure less stable. Neither of those is a problem if you make it clear to Google that your content belongs on a subdomain.