Mo... you do raise interesting points, however I would like to firts come to a conclusion with this question before going off on Windows' security. I will say that a combonation of the second SID, traverse directory (/execute which I figured would only complicate this thread by including) setting, and the "start in" setting are what makes this work.
I do have a tutorial started on Windows client sandboxes started... and I am quite familiar with that document (I believe I may have even referenced the ACM copy here in the past). I think this would be a good area of conversation, I just want to keep on point here as this about about a requirement and how Linux meets it.
cheers,
catch
