Also, operating systems should let us set filesystem permissions per app/process/executable instead of just user accounts.
Similar to how macOS/iOS Sandboxing works but at a more lower and granular level
Similar to how macOS/iOS Sandboxing works but at a more lower and granular level