> Did Apple claim it would impact sandboxing? I don't think they did.
Apple claims that security would be impacted. They implied that sandbox=app store. Its all FUD marketing, of course, but they heavily implied that the app store review was the safety method for customers.
> if your iOS app wants to track users, it must go through AppTrackingTransparency.framework, which allows the user to opt-out, and use the device’s advertising identifier which the user may reset.
No reason you can't make access to the ATT DeviceID a call to OS. It'd return 000000 in generic case, and prompt the user at OS level to approve. If no approval, then it'd return 0 to app. You can't guarantee what they're doing with the number in-app, but apple barely does that now with review so probably not much loss. Sure some apps could try to access restricted memory or file paths that they aren't supposed to... but thats what the sandbox is for. BUT maybe apple should just kill DeviceId for everyone since im sure most people opted out.
The real loss to apple is that first party apps may have to play by their rules, and lose access to privileged APIs, or open them up to sideloaded apps (since the trust boundary is moved from source of app, to OS calls). They don't want to have to play by their own rules.