well for Desktop/Laptop machines, what you said is true. Everyone stores some sensetive info in these machines and security is important.
However for RPi situation is not that critical, and that is why first login with default password is allowed (with a advisory note to change default password). By the way most of Pi users ignore this warning and continue using default password. The reason is one cant easily forget the default password, and if one does, he just asks in forum or Google, and readily gets it.
.
Quoted below is my old post on RPi’s security issue
Nothing serious, just a joke