Every web server has the ability to specify the user -- say, nobody or www_user -- that the server will run as. It uses high privilege to open the low-numbered ports, then immediately (and, irrevocably) becomes a non-privileged user. It's a one-way street, they can't go back. Furthermore: if you are using FastCGI, the worker processes never need to have high privilege, nor necessarily the same user-ids.