Because it is trivial for unprivileged malware to phish the password and escalate to root. No production system should ever ship with sudo.
No desktop system is safe from your attack, unless you take specific precautions like chattr on the file or chmodding your home directory, but that can lead to weird breakage.