Stealing Secrets from Developers Localhost Development using Websockets

What is the reason behind having check_origin: false in developments? Why not keep it as in production?