i think that for avoiding anyrisk of Mr Lambda getting someday wormed or rootkited or whatever, why not putting quite restrictive default firewall tables?

leaving nothing open (except for ssh?) would be a good idea i think...

the thing would be to specify that somewhere, so when Mr Lambda will want to make his own webserver, he'll take care of opening the corresponding ports...

maybe puting some graphical firewall interface (and monitor?) could be useful, in the vastness of the gnome-earned space?