Having had the (dis)pleasure of working with SELinux, it's clear that there are systems out there that can work to solve these problems. On Linux the problem is in the UI/UX layer (actually configuring SELinux rather than working around it is a massive pain) but Apple/Google/MS have the money to solve that.
I don't know if Apple has something like that. Surely they must do; Windows FACLs have been available since NT was part of the name, Linux has had them since Linux 2.5, and Apple invented a whole new filesystem relatively recently. They've also compartmentalised iOS apps since they were first released.
I'd be surprised if the currently available APIs aren't usable for applying effective restrictions just yet. Rather, I think Apple's choice is part of a process to move desktop applications towards the iOS model instead.
Having had the (dis)pleasure of working with SELinux, it's clear that there are systems out there that can work to solve these problems. On Linux the problem is in the UI/UX layer (actually configuring SELinux rather than working around it is a massive pain) but Apple/Google/MS have the money to solve that.
I don't know if Apple has something like that. Surely they must do; Windows FACLs have been available since NT was part of the name, Linux has had them since Linux 2.5, and Apple invented a whole new filesystem relatively recently. They've also compartmentalised iOS apps since they were first released.
I'd be surprised if the currently available APIs aren't usable for applying effective restrictions just yet. Rather, I think Apple's choice is part of a process to move desktop applications towards the iOS model instead.