>The history of local root exploits ("Cheap and easy!") would argue that doing such a thing and relying on the kernel is just security theater.
it may not be perfect but surely its better than nothing. it wouldn't protect you from a sophisticated nation state attacker, but most people don't have that in their threat model. surely it would be good enough to prevent google chrome from snooping through your home directory and other such things.