> I'm not worried about malicious users. I'm worried about household guests and family members.
Are you well aware that with physical access they're able to do anything anyway? In most setups family members can. When it comes to guests, the right tool for you is xguest -- you'll get a locked-down desktop for guests with no extra configuration at all.
For the rest of setups you can still change the policy; point is that defaults are sane for most setups.