Totally agree. The problem is the idiom of using mass assignment, which IMO should almost never be used.
This is not a bug or a security hole in Rails, but an issue with programmers not paying attention.
If Rails had no attr_accessible feature, it would be standard practice to always filter attributes in the controller, and no one would call this a rails issue - they would put the blame where it belongs: Github.
Instead, because attr_accessible exists, people are flaming that it should be enabled by default.