是不是特别大? It depends on your applications. Certain document management system (DMS) need to pre-define the administrator password in its own configuration file. If you set everything under www with 777 permission, then anyone can become the administrator! Not good!
Again, it depends on applications. However, under any circumstances, we should not let unauthorized persons to read system configuration files, esp. when passwords are stored in plain text.