As a user I'm not realistically going to audit every new line of code in a piece of software with every update (if I even can) and I do not at all like the current model where we have to trust software creators blindly. It's the reason anti-virus/malware software is necessary on Windows.
As a developer I would much rather that users don't have to trust us blindly, "this app only needs an internet connection and access to this one directory" would be a far easier sell than the current scenario.
Popups, in the Windows UAC sense, yes, those are utter shit and train users to automatically give permission. Giving specific permissions once, more like Android, is much better.
Then again, no one who needs an actually useful computer runs Windows in S mode.
That's because of all useful apps for Windows are not sandboxed. This is where the apps vendor have to do the required work but they are too lazy to do that.