There is a lot of middle ground between “every app can do anything as the user” and “no shared file system, no user access to app ‘owned’ files”.
There is a lot of middle ground between “every app can do anything as the user” and “no shared file system, no user access to app ‘owned’ files”.
Any time big corp implements strong sandboxing they'll inevitably put the user inside of the sandbox.
That's a valid concern, but not an argument against sandboxing, in my opinion.