https://twitter.com/lemiorhan/status/935581020774117381
Bottom line: Easy to get root access with a blank password by using multiple Apple utilities. Set a root password NOW. Do not just disable root. Leave it enabled with a crazy password. If you disable it then the utilities will simply allow for it to be re-enabled.
All it takes is for someone to figure out how to get Apple Script or some other scripting bit to open root via a web page or some remote method to screw millions of Macs.