You're free to say you don't care, but it isn't really valid to brush aside the point by pretending a security model that's there for a reason isn't there.
Also it isn't uncommon at all for an attacker on a server to get access to a regular account and not a root account in their initial vector. It is often too easy to escalate, but do you really want to help them out more?