  In the current version of <A HREF="http://simon.cs.cornell.edu/Info/Projects/HORUS/"> Horus</A>, it is possible to maintain process groups whose semantics are weaker than those of virtual synchrony. In such groups, it may be desirable to permit untrusted processes to join. An example of this might involve allowing untrusted clients to join a client/server group. In such a setting, servers would communicate with untrusted clients, but would only accept a limited set of commands from the clients (and would be responsible for screening out all other messages).  <p>
