I think deep inside you do understand the difference between immediate root access to a system without knowing anything at all and spying on somebody to learn their passcode. And even if I do agree it's definitely a change for the worst it doesn't deserve they same hysterical response the root no password required bug deservedly got.
the root password hack also required physical access, or some sort of proximity access on a network LAN, to be able to work. It’s really not that much different than snooping on someone sitting a few seats away from you at the bar