Earlier quoted context omitted.
You can do strict sandboxing on Linux, too (e. g. with Flatpak).
Yeah, but that only sandboxes the applications that opt in. If you want to stop malicious applications from doing malicious things, even when the system owner unwisely grants them permission, you need mandatory sandboxing that the system owner can't bypass. And that isn't compatible with the free software ethos.
I think something similar could be compatible with free software ethos.