> You're missing the entire field of remote exploits. Meltdown, for example, could be exploited by JavaScript code running as non-root.
Yeah and that was a really big deal. Fixes were pushed in record time.
> It's about what software can do to somehow gain access to root's privilege level via exploits.
The correct way to deal with that is to plug exploits or write code that is less likely to be exploited. Taking away privileges from root is the exact opposite of what we should be doing.
Root access should be protected, and any bugs that break this barrier without the user's credentials should be fixed/prevented.
The root user should have absolute power to do anything. This is the basic ethos of Linux.
Taking away power from the user results in ios. I don't want Linux distros/systems to start behaving like ios.