> Even on the desktop, the square peg is not the correct shape: we know that the system will be used by a single person and that the system does not need to protect the user from non-existent other users.
I don't know if this is really true. Many desktops are shared (e.g. by members of a family). And of course data centre machines are shared by multiple users, although often those users are all using processes operating using the same OS credentials.
Wouldn't it be interesting if processes running on my behalf within Facebook or HN couldn't access other users' private data, rather than relying on the programmers at FB or HN to get it right?