It's better to have root access disabled by default on phones sold to the general public since they are more likely to just click the "Allow root access" button because they don't understand the security implications of allowing root access.
CyanogenMod has never allowed sudo without confirming it with a UI, or only allowed it for a few days back when it launched.
A user that does not know what the security implications of root access are will most likely just click "allow" when presented with a dialog