Alright people, I created this account for the sole reason of saying this, so Listen up! I read through this entire thread and have one thing to say that hasn't been mentioned by anyone else.
The simple solution to preventing any of the Private packs from going viral is in the Server.jar. If you don't distribute the Server files, then you won't have the potential problem of a bunch of people making servers and using your private pack that doesn't have all the permissions. Unless someone else took the time to compile a server with your pack's mods on it, there would only be the one server with those mods installed, and without the server IP, the pack would be largely useless except for single player.
I encountered this experience firsthand a few days ago when I got an e-mail from a server I used to play on about getting a limited edition key for a private FTB pack. It interested me, so I went through the short process and got the key and it worked, I've got the pack, But I have no idea what the server IP is yet so the pack is kinda useless for me because I don't play singleplayer anymore.
So that's my point. So long as nobody posts the Server files, there will usually only be one server running that pack, preventing ones that lack permission from exploding into mass popularity, and without the I.P. to the server that is running the pack, it's only good for singleplayer, possibly LAN mode as well, but that's it.
With this amendment to any of the ideas stated previously, the majority of the risk is removed. If any of you can think of legitimate reasons why this would not work, or if it's been mentioned why this wouldn't work, Please let me know, because I don't see any problem.