The kernel should mount it read-only. If root wishes to delete or modify the contents, root can remount it read-write.
Not necessarily. Leaving it "wide open" for anything to accidentally write to it all of the time vs. just mounting it readwrite when you actually need to write to it are two different risk profiles.
The kernel fix doesn't have such drawback.