There are no doubt going to be some security features to clear up.
1) You can download any file - probably a way to check if the requested file lives inside the shared folder. If not, the request is denied. I know people would have to know the exact location and path, but even I could probably guess the location of my friend's chat logs for example. Of course he would see that I had transferred the files
2) Could also have some kind of allowed users list. Not on the list, you can't get the files.
3) Some kind of login, or password protection type thing.
In any case, nothing is totally secure. If you are worried about people getting your files, you would never connect to the internet
I'm sure Pleh will address many of these problems with future versions of his plugin
