Raspbian disabled that as a default a while ago because there's no good way to have ssh login by default without having default username and password be public info.
They could do something like have the default password be something embedded in the silicon like Apple's SE master key? And the print that key on the underside of the Pi so only people with physical access can read it.