Above all, we need a true privilege separation API at the application level. Why is the only way to sandbox my code editor to run it in a Linux VM on the Mac? And that’s solely to mitigate supply-chain attacks.
The simple root/user separation has long since ceased to be secure because, on a desktop machine, all sensitive information is, by definition, accessible to the user; having root privileges ultimately offers little advantage when it comes to exfiltrating data.