I run my private user account under umask 027, I also chmod all my files to 640 and directories to 750..
If the user can browse your files via "file://" in Firefox, they can do it from xterm as well... hide stuff that's important to you, if they can evade file permissions... use OpenSSL to encrypt the files.
|