Sun Jan 22 00:12:09 EST 2012

I think this is bad advice.  Protecting against the KDC impersonation
attack is a good idea, but not horribly vital in a lot of environments,
whereas making general applications setuid root is a serious security hole
waiting to happen.  I would never do this.  (And it's no longer necessary
for anything using pam_unix on most systems, since it uses a setuid helper

Most screen savers are not written for or audited against running setuid

