First, that presupposes that they have a shell account on the machine. They may not. Second, that would allow them to remove all files that /they/ have access to delete. The OP's program might be (e.g.) a CGI that is not S(U|G)ID but is not run as that user, either.