Assuming the automount works even if the screen is locked (as I get the impression is often the case), this is a perfect way of breaking into someone else's machine. If the exploit opens a root shell on a secret port, that machine is now owned ...
So in that case, the user knows exactly what is on it. They want to see what's on the machine.
So a confirmatory pop-up (as I get on my gentoo system) *is* a very effective security step.