If my user account is compromised, the attacker can ruin my credit and reputation, end all my friendships, drain my bank account, and sell my entire life history to an eager 3rd party.
If my root account is compromised, the attacker can do all of those things as well as add a printer, or delete a file that I can download freely from the Internet. I don't really care about that additional attack surface.
[1]: https://easyos.org/about/how-and-why-easyos-is-different.htm...
FINALLY. One step closer to a more modern mobile-like untrusted-by-default setup.
It has gone on way too long that any standard installed program can spy on every other program/all your data on the system.
Now in this case where the user is root it might work out as an interesting balance in practise, I'm not sure.
For the group of people who want to use an app but not a computer, I think something closer to the iOS model is probably better.
For my work computer I want something more traditional but for my personal computer, my phone, and my game console, I want something more appliance-like.
Both of these ways of doing things currently exist (and there are others) and I would guess that will continue to be the case for a long time.
Not disagreeing, but, the threat model of the creator of Puppy Linux may be different than yours.
if you're always careful to run as a non-privileged user, the most that could happen is that a browser vulnerability allows arbitrary execution of code as your user, allowing deletion, encryption, exfiltration of your personal data. so you're boned anyway.
In the traditional Linux desktop model a vulnerability may allow to run something as the user. It can change your bashrc, your application menu as well as your launchers, your browser extensions and settings. You may already have a user writable directory in your PATH so it can replace things even on a lower level.