> And then a lot of apps just ask for full access to your home folder or even to the whole filesystem, just so that they can open documents.
Therein lies IMO the biggest problem with application security on desktop Linux. Just like selinux, apparmor and other similar security tools *someone* has to globally deny access to permissions, break things in the process and find the minimum number of permissions required for the app to function.
Many users are not going to do this and (lazy or uninterested?) developers (package maintainers?) don't want to do that work either.