-- https://twitter.com/TartanLlama/status/1375045731644538882
Except we have some grandfathered file types that are implicitly trusted.
until ... one day ... they are!
For instance the dropbox binary can only access "/home/dropbox" and "/net/dropbox.com" if this was more well-known/used.
In POSIX we only generally get a user/group level of granularity which seems to practically mean that only daemons are completely isolated.
I honestly don't understand how anyone with at least a basic understanding of how OSes are designed and operated could ever arrive at that conclusion. The layers of wrong assumptions required to support that assertion are in the level of "not even wrong" confusions.
Would be nice if the operating system could set up a fresh, temporary "user" for each application installed, and instead run the application as that user, who starts out with no access to computing resources. Maybe some existing systems already sandbox apps into their own unprivileged users, I don't know, but it would probably be very secure.
But often when such sandboxes are attempted, it turns out that it often became more complex than originally thought, and applications need many resources which were not originally considered, so they are given those resources, and very often those resources can be used again to construct more resources or otherwise to some measure escape the sandbox.
I fail to see how HTTP and REST's "everything is a resource" paradigm is significantly different than UNIX's "everything is a file" paradigm, and I'm yet to see anyone claim that the freedom and power to open any HTML document (OMG a file!) made available through the internet is a mistake or a bad design decision.
On the other side Unix has users and permissions, HTTP does not and you have to build your own.