The default umask in Pinstripe is 002 (rwxrwxr-x). While this is fine for the default setting where each user belongs to his own group, it is less suited for the scenario where each user belongs to the same group by default. In that case, this umask is fatal security-wise. I think that the umask 022 (rwxr-xr-x) should be used as the default, as it is safe in both scenarios.
As discussed on testers-list, we aren't changing this.
My bad. Closing this.