Traditional UNIX is no different. Without containers every p0wned process has full access to $HOME and can do everything the user is capable of.
I really like that Apple and Microsoft are pushing for sandbox models in their OSes.
I really like that Apple and Microsoft are pushing for sandbox models in their OSes.
Of course there are things like HP-UX safes, Tru64 and Solaris trusted zones.
None of them are POSIX.
Besides the average user would not even know where to start.
You can use VMs for some of that, but that's the limit on sharing (and that's if you trust your hypervisor to be a separation kernel thing; reasonable for many people. Not for others.) Docker/containers isn't enough. Users aren't enough. Processes aren't enough.