This has been the default for quite some time AFAIK. None of the distros I've tried for at least 4 years left the X server authentication process open (they were at my school though, and that was "fun", kind of).
To check this out, just run the xhost command with no arguments. It should reply this:
fg@rtfm ~ $ xhost
access control enabled, only authorized clients can connect
If you see this message you're safe: no one can connect to your X server unless you type xhost +some_host.