Oh, you have a policy problem rather than a technical problem. In that case, I'm not sure how it would help to have a system where user control was normal, since invariably it would be locked down in exactly the same way. I don't think HURD will prevent mounting /home with noexec.