it's easier if the sftp-server does chroot. however you need a setuid sftp-server. additionally you have to disallow writing of $HOME, restrict sftp to subdirs only. otherwise the user can modify .ssh or .forward... -m