Problem with setting secure defaults, is that most of the worlds PHP would stop working properly.
We are talking about an ini file. This isn't rocket science.
However they will now be aware that said feature is insecure and should know the consequences of enabling it.