I tried that, and it does prevent unauthorised people from getting in
as long as they don't use the SharePoint machine itself.
I found that by using the SharePoint machine, and logging in as the
Administrator, I was able to browse to the folder and view any files
inside.
I even tried creating a file inside the folder that explicitly denies
the Administrator access; this has no effect. The Administrator could
not check out/in the document, but they could read it.
Anymore ideas anyone?