The reason not to do that is that dev.example.com can set cookies on example.com and other envs can see them.