pre-login fun

one of my friends noticed that when he goes to login to my hurd box, he can
do stuff before he gives any kind of username, password pair.
i have verified this in that one can navigate around the filesystem, looking    
around different directories and such.  one can also fill the partition by      
typing 'dd if=/dev/zero of=/tmp/blah'

is this normal, or have i done something boneheaded in the install process?
if this is normal, doesn't it strike you as a bad idea to allow                 
non-authenticated users even read access to your filesystem?  if i have done   
something wrong here, any advice on fixing it?           

thanks once again.

