Oops, hijacked the thread in a manner of speaking - apologies to you and the moderators (who will no doubt give me what for...) What now? I was just being curious with my first post to this thread.
To answer your question, I used the standard ibay setup:
Write=admin, Read=everyone. So I set the perms manually for /sites/default/files so that Drupal can write there, but if one were to, say restart the server for some reason, Drupal can no longer write to that path.
Cheers,