You wrote "the standard 'wizard' ". Do other distros autocreate a user named 'wizard', or expect the sysadmin to create one if needed? Also, why not create a *group* named 'wizard' instead?
P.S. Should priority on this bug be bumped to, say, normal? I see no reason why users who want to run nethack in wizard mode should have to expose their systems even to a minuscule risk of data corruption. As the Security section of the Release Critical Issues for Etch document says: "Programs must be setup to use the minimum privleges they can. (ie, not setuid where setgid will suffice; not setuid root where setuid some other user will suffice; setuid root for the minimum period possible, etc)". (http://release.debian.org/etch_rc_policy.txt) Yet this bug only forces users to run nethack as root if they want to use wizard mode, not for the rest of the game's functionality, so it's not as bad.