Computer science solved this problem (the "Confused Deputy" [1])
decades ago [2] [3] with capability-based security [4].
I don't have the time to find the exact reference I'm thinking of right now, but consider taking a look at one of the papers that give a background to CapDesk [5]:
> Which addresses, among other things:
> "All Windows and Unix operating systems (referred to as “Winix” hereafter) utterly disregard the concept of POLA [Principle of Least Authority]. When you launch any application—be it a $5000 version of AutoCAD fresh from the box or the Elf Bowling game downloaded from an unknown site on the Web—that application is immediately and automatically endowed with all the authority you yourself hold. Such applications can plant Trojans as part of your startup profile, read all your email, transmit themselves to everyone in your address book using your name, and can connect via TCP/IP to their remote masters for further instruction. This is, candidly, madness." [6]
Since then, things have changed slightly - UAC under Windows, for instance, means applications now only have the ability to steal and hold your highly valuable and personal documents for ransom, but hey at least these sneaky trojans don't have admin rights! Which is of course the exact scenario that Cryptolocker happily exploits.
There's really no reason a piece of junk attached to your email application should execute any more authority than you explicitly grant it. (And no that doesn't require clicking a bunch of buttons to "Allow" access -- intelligent UI design can make much of this completely transparent, provided the host platform is capability-based.)
It's not that companies like Microsoft aren't well aware of capability-based security [7], it just seems to be that the appetite isn't there to really solve user's problems (breaking stuff like the Start Menu appears to be more important), despite the valiant efforts of some really smart people [8]. To be fair, shifting to a capability-based system would be a significant engineering effort, but definitely well within the realms of Microsoft or Apple's capabilities.
(Interestingly, some of the ideas on erights.org were influenced by Nick Szabo, who created "Bit gold" and who a few people think might be Nakamoto himself [though he denies it] [9])
[1a] http://www.cis.upenn.edu/~KeyKOS/ConfusedDeputy.html
[1b] http://erights.org/elib/capability/deputy.html
[2] http://www.cis.upenn.edu/~KeyKOS/Gnosis/Gnosis.html
[3] http://www.cis.upenn.edu/~KeyKOS/Key370/Key370.html
[4a] http://www.skyhunter.com/marcs/capabilityIntro/index.html
[4b] http://erights.org/elib/capability/3parts.html
[5] http://www.combex.com/papers/index.html
[6] http://www.combex.com/tech/edesk.html
[7] http://research.microsoft.com/en-us/projects/singularity/
[8] http://en.wikipedia.org/wiki/Capability-based_security
[9a] http://erights.org/related.html
[9b] http://unenumerated.blogspot.com/2011/05/bitcoin-what-took-y...