With the amount of information leaks that have occurred from S3 buckets being public, I'm surprised this wasn't fixed a decade ago.
You are, inevitably, going to break someone's workflow for a reason that you cannot possibly fathom. They are going to be unhappy. At least one of them is going to come across your boss' boss' desk and they're going to wonder if this change is _really_ necessary.
Every incentive, even with this default behavior being bad, is to leave it the way it is.
Respect to the AWS people that got this across the line.
You need to remember the S3 API is from 2006 and Amazon probably measure how many buckets are created with these 17 year old defaults and then actually stay and rely on these defaults.