Most devices should be limited to mode 640, unless the group is untrusted, where group read access may need to be limited. /dev/null is the exception, and it should be mode 777.