All this to say that Wayland might be the new go-to for new users since they can't tell the difference? Idk.
Security has always been a hard sell to end users because the costs are immediate and tangible while the benefits are in the future.
In the case of a bridge, in terms of material, time, and money. In software, it depends on the program, but it's usually some combination of performance (e.g. encryption), cognitive overhead (remembering passwords, access policies, ...), accessibility, development time, and a few other things. And notably (for Wayland), features --- locking down a system naturally reduces what a system can do. Note that this overhead can be a blocker. Accessibility is an obvious one (e.g. take those numeric keypads that randomize the order of digits presented on the display each time you want to unlock them --- blind people will not be able to use those), but features can also be a problem: if part of my work requires commonly taking screenshots (e.g. because I work as a technical writer, and need screenshots for documentation reasons), then I won't be able to do my job. In fact, the corporate world is chock-full of (maybe even sensible!) security policies reducing efficiency of workers, or sometimes outright blocking work.
What I'm trying to get at is, security requirements depend heavily on each user and use-case. And I think Wayland's fallcy was in trying to shoe-horn everyone into this vision of a fully-sandboxed world without considering the practicalities and what people actually want or need.
For example, I keep my personal desktop (which I mostly use for gaming & FOSS work) far less secure than my work computer (which is also in my apartment, as I work from home). Because I've deemed the overhead of trying to better-secure my desktop, unlikely to get stolen from my apartment, as unnecessary overhead. Meanwhile, my laptop, which I also use for gaming & FOSS work, is more secure, as I tend to take it with me when I go on a trip. Because while the severity of a breach is the same as for my desktop, the probability is much higher.
So I have three situations, and I'll argue that no single security policy would be a good fit for all 3: (or even two) - Home desktop => low risk of breach, moderate impact if breached[*] => low security - Home work PC => low risk of breach, high impact if breached => high security - Laptop => moderate risk of breach, moderate impact if breached => medium-to-high security
That, I think, is part of the issue people have with trying to sell Wayland's flaws as "security". It's basically a one-sided "I'm changing the security policy, and you better pray I don't change it further". When said security might be more than just undesirable, but an active obstacle. At the end of the day, Wayland is a tool. It has a job and a purpose, and yet it can't even properly do some things of the tool it's meant to replace. Because "security".
([] If you disagree that it's an overhead, then I'm going to expect that every single door in your home, even the fridge & closet doors, are packed with as many heavy-duty locks as will fit on the physical door. And that each door is always locked unless you're currently actively interacting with the door. For starters.)
([*] Yes, I realize the issues with an attacker being able to access all my accounts and such, but I'm putting it in relative terms compared to the work PC.)