We're extremely aware that this isn't ideal, and is more or less the first thing we're working on fixing. It's why we have this listed both under "Causes for Concern" and "Strategic Improvements". The order of those issues isn't done so by importance :)
Theory: ALWAYS Encrypt. No exception. Don't let software go into production if it's not.
Practise: Always encrypt. Aw wait... what do you mean "tls is not supported?" Are you saying that half of our applications have been running on bare HTTP for years?. Mehhhh. Well, all our public accessible websites are running on HTTPS, right? Right. Guess it's only half a disaster after all:(
No. No. No. No. No. No. This should NEVER be an option. You should not allow data to pass unencrypted over the wire, period.