Earlier quoted context omitted.
> To be fair, Linux and friends aren't much better in that regard. Linux gets there a different way. The standard way to install applications is from the package manager and essentially all of the applications in there are trustworthy (because they're all open source and if they did anything seriously user-hostile, someone would fork it and that version would be the one in the package manager). Meanwhile the package…
Package managers are exactly the centralized "app store" model, and there have been plenty of periods where users have had to add third party repositories to get basic functionality (DeCSS, video codecs, ZFS, etc). The difference is that Linux repositories are less noteworthy to attack, have a more distributed culture not ruled by capitulating lawyers, and can actually jurisdiction shop. The ultimate problem is a lac…
And they still work precisely because the user can do that.
> For decades we've been continually looking for better ways of isolating local apps, while also rejecting centralized control.
The main issue is that there is so little real benefit in it. It's possible to isolate e.g. LibreOffice so that it can't access anything it shouldn't, but in general the authors can be trusted not to be doing anything nefarious to begin with, so what you're really doing is limiting the damage in the event of compromise. In which case you're still pretty screwed, because it inherently needs access to your documents, so the focus has not surprisingly been on preventing compromise rather than mitigating after the fact.
> We keep looking, while centralization keeps ratcheting.
The motivations behind the rise in centralization are authoritarian and pecuniary rather than any legitimate security concern. Trying to prevent it by finding alternative ways to improve security is like trying to repeal the DMCA anti-circumvention rules by finding alternative ways to reduce piracy. They'll never be satisfied because their motivations aren't the stated ones.