Agreed that is a bad stance from a security standpoint. Security updates will always be coming , users can not be relied on to always update so you get sites that will never be updated and eventually hacked and spam/ scan / redirect to malware and create a bad experience. On your average shared host drupal would be set to write to itself anyway since php will run under the same username of the files. I guess permissions could be set lower to 444 to prevent this - but the fact Wordpress will auto update the core is essentially to security.