I was just playing with dreamhost and you can browse into other people's directories!

I just went back a level in the structure, picked an NSF mount (they start with periods, as if that hides them or something), browsed into someone's directory, went into logs (which is world viewable and tells me the name of their domain name), checked out their access log (which would show me any password sent via GET), browsed into their web directory since now I know its name, and explored their files, including finding out their wordpress mysql password. As far as I can tell, this works for EVERY user, and you can't secure it because if any of those directories are set with non-world-readable permissions, the hosting won't work.

Wow.

Time for me to find a new host. Any recommendations on a host with similarly large quantities of storage and bandwidth, but that is secure?