Technically the people with webservers with php scripts on don't have untrusted local users, they have *malicious* local users that they don't even know are there (as soon as an attacker gets in at all). This is of course worse, because as you suggest they'll often have thought 'ooh, I trust all the local users', which is poppycock.
It's like a filter making sure that everyone who manages to become a local user has larceny in his heart...