If a system isn't running shadowed passwords, he'd have read access to /etc/passwd already. (Unless someone has taken the time to chmod 400 /etc/passwd, which... hmmm... I don't know what would break. Time for experimentation (system security for the paranoid. :=))

If it's using shadow passwords, he doesn't have access to it anyway.

On HPUX 11.0, with ksh, it doesn't do anything.