Maybe a bit off-topic for this comment but I really like (most of) the web's security model and I wish I had the same on my desktop. Specifically I'd like a strong per-program permission model, ideally in some sort of pluggable fashion (like, have a configurable chain of programs determine other programs' permissions, à la middleware).
You could take this to the extreme and have every program run in a "pure" fashion per default (i.e. no inputs other than command line args - no outputs other than the exit status).