Well, that article was scarily informative. It turns out that my gut-feel about a kernel implementation of the basket-of-holes that is SMB is correct - it's full of security risks. I know they've fixed loads, but at this late stage, we should be down to security researchers finding esoteric corner-cases, not ordinary code-reviewers going "er, where's the tests for this case?".

Pray $DEITY there's a kernel option to turn this sucker off!

