I think this module needs to offer some basic information about how security limitations in different types of hosting environments can affect the results of the module's reporting. Similarly, a prominent disclaimer to emphasize the limitations of this module ability to examine file and directory permissions on a server may also be warranted.
While there's probably some value in scaring to death anyone who expects anything resembling security in a bargain basement shared hosting environment, the reality is that a very large number of users (for whatever reason) have Drupal setup in shared hosting where the ability to set ownership of files is limited. I think developers in this situation need to be educated about the risks and also given tools that will allow them to do the best they can with security in the environment they're in.
This struck me as I was reading this http://drupal.org/node/628776#comment-2466128. There must be a huge number of Drupal installations in shared hosting where the webserver runs as a user who is also the file owner. In this scenario, as I understand it, there's little to be done to 'fix' most of what is being reported by this module because there is only one owner for everything. In this scenario, there's really nothing to be done to address most of what shows up in the system permissions report – short of changing to a different type of hosting environment. I think this warrants some explanation.
Comments
Comment #1
videographics commentedMaybe directing users here http://groups.drupal.org/node/138134 will be enough.
Comment #2
gregglesOr we could elevate the quality of those hosting environments so they provide users with higher quality solutions?
Comment #3
gregglesWorks as designed from my perspective.
Comment #4
videographics commentedYeah, I've come to that conclusion too.