Earlier quoted context omitted.
“Everything’s a file!”
perhaps this is the worst possible abstraction to be protected by a security framework.
Would be nice if the operating system could set up a fresh, temporary "user" for each application installed, and instead run the application as that user, who starts out with no access to computing resources. Maybe some existing systems already sandbox apps into their own unprivileged users, I don't know, but it would probably be very secure.