For more info and additional options and tips:
For better user isolation the create user script now creates a new group too, based on the username and assigns the user to this special group.
- users can still ls each others home folder (can't the subfolders?)
- users can "Su" to other users
- user uid and group gid generation is not concurrent safe