Any business that has a telnet daemon able to be reached by an unauthenticated user is negligent. Just the fact that everything is in the clear is reason enough to never use it outside of protected networks.

unless it doesn’t matter if it’s evesdropped

Traffic could be tampered as well.

Sometimes that doesn't matter either. That is the valid use case of a plain-text protocol like telnet: doesn't matter.