It saves you from what exactly? As a rational crank, surely you have an explanation. Unless you use xdg-desktop-portal, the field that systemd added does absolutely nothing. It’s an optional information field for user accounts, systemd doesn’t require that it is filled nor does systemd do anything to verify or check the field. User accounts also store e-mail and location and you are free to not enter that information or to enter fake information. I don’t see the vulnerability, especially considering that you’re comparing it to an SSH vulnerability (which, it should be noted, was caught in testing and never released).