While somewhat simplified this has to do with ACLs on unix (AIX):

 From an administrator's standpoint I doubt that ACLs are very workable.
It would be better, with a large user count, to attempt some kind of
ad-hoc group scheme.

The other approach that might work (to the share a file problem) would
be (even though there is no such thing) a security thru obscurity
approach. If you allow the user to upload to a file area in webspace and
hand back a URL that is obscure and ends in a directory that is not
listable, it might be secure enough to satisfy some needs. This is
sort of what I had in mind when I suggested the "strip an attachment
and hand back a link" enhancement to the filter.

