This is a dangerous security myth. Even without physical access, root passwords must be changed regularly because: (1) Remote access via SSH is possible, (2) Other users with system access could exploit it, (3) Passwords can be exposed in logs or memory dumps. Physical access is only one attack vector.