Bernstein wrote qmail, which can safely claim to be the first modern least-privilege mail server design, and one of the first modern least-privilege designs of any sort. qmail tries to derive some additional security from splitting up its activities into multiple components running with different credentials. Despite qmail's extremely impressive security record (it is one of the most impressive bits of secure code ever written), Bernstein considers his privilege-separation experiment a failure.
http://cr.yp.to/qmail/qmailsec-20071101.pdf
The problem is that minimizing the capabilities of a computer program often just moves the goalposts for an attacker. Too many times, unexpectedly conceding to an attacker some privileges on a target results in a compromise of all meaningful privileges, because attackers can use those new privileges to launch further attacks.
The problem is even harder in modern web applications, because breaking the operating system almost doesn't matter; all the attacker really needs is a working handle on the database.