Do you trust this application?
blogs.gnome.org
blogs.gnome.org
Throw phone-home & disk access restrictions into the mix and I'm even happier.
I know there are sandboxing tools for linux desktop -- the community needs to identify one that's easy to use and start using it. Let's recruit closed-source OS users to linux by dangling easy-to-use privacy.
Also, at least for his examples, these are fairly low popularity products, as much as I like Gnome[0] and its ecosystem, it's the truth. Shotwell? He said it himself, no one develops it anymore. Epiphany (vs. Firefox vs. Chrome) Gnome Music, Weather? It doesn't help that the userbase is small and thus, the developer base is even smaller.
Would we see the same apathy with Firefox, VLC, mplayer, not to mention bash or openssl? Probably not (as we have seen especially with the last two).
[0] Not being sarcastic, imao, Gnome 3 blows Unity,Gnome 2,KDE, and even OS X out of the water in my book, which makes me sad it isn't as popular as Unity.
No idea how other distros solve this issue though. And on Windows with its lack of any package management or update facilities other than whatever homegrown stuff the vendor ships (which leads to dozens of updater processes eating up RAM) the situation is even worse.
But it's worth pointing out that at least with free software, we are able to assess just how (in)secure an application is. So we can find out which applications to use or avoid if we are interested in security. The same cannot be said for proprietary applications.
Realistically, most people aren't going to do this. A more pragmatic solution is to use a minimal system, where for every task, you always use the smallest application that will perform it in an adequate manner. With proprietary software, you seldom get the ability to set up such a minimal system.
In particular, this means that I will never use a desktop environment, because there is no task for which a desktop environment is the smallest, simplest possible solution.
Everyone was shocked that like one person was maintaining OpenSSL which everyone depended on, some of the mentioned programs have exactly zero people maintaining them. The package maintainers will do the minimum to get them to compile but that is it. So once you've got a remote execution bug in a commonly shipped but unowned piece of code, you can rootkit all your friends who use it, again and again and again.