why are images shipped with an empty root password?

would it not make sense to generate a random password that the user can look up in the menu system?