Well, I think I'm going to fool with keep a single userid with two
usernames. The /bin/false account will chroot to ~/public_html or some
other part of the web tree. Thanks Don for pointing out the issue with
ssh; this is really the kind of oversight I was looking for. I suppose one
could also set PermitRSAAuthenication to no, but that'd be no fun. 

As for the issue of the account with a shell being able to exercise full
control over the pop/ftp account: it seems moot to me. The idea is that
you're safeguarding against the compromise of system resources and not
the web site or e-mail of a specific user. Sure that would be nice too but
if those users insist on using insecure protocols like pop and ftp then
that's that. Besides when was the last time you heard of a non-targetted
attack aimed at data compromise and not resources?

