Indeed. That's precisely why some browser vendors don't want to give random access to your computer to any and all website. And don't want to give every app and site access to the data that should be private to a particular web site.
From this point of view sandboxing websites seems like a good compromise.
---
It's also strange that the argument I keep hearing is "but apps have unrestricted access, so to preserve security and privacy... let's give web sites the same access as native apps". It doesn't work lime this.
Indeed. That's why browser vendors (well, some of them) take a dim view of "oh just let them access anything, just pop a confirmation prompt in there"
> There are permission prompts, privacy controls and access limits.
And users are surely aware of those and can definitely understand where to find them, and what implications those have? Literally the entire history of computing tells us: no.
> This is not at all "random access to your computer"
It is. This is already done by MacOS with its incessant "app X wants to access files in Y". Even I, a programmer, and a power user, end up clicking "to hell with it, yes" more often than not. Especially if I'm in the middle of an important task.
Of course this happens a lot after installing a new machine. Once I have my machine running however, I don't encounter this anymore. I think it has to do with the fact that I very infrequently install new applications.
In at least one of those cases I was like "you want my Downloads? Fine, go away" because I was in the middle of some task :)