Here's an interesting project we should integrate with macs at some time: http://dazuko.org/ it's a linux kernel module that does run time file ACLs.
View entire thread