OSs need to stop letting applications have a free reign of all the files on the file system by default. Some apps come with apparmor/selinux profiles and firejail is also a solution. But the UX needs to change.
replies(5):
I use it all the time, but I'm still looking for people to review its security.
A locked door is better than an unlocked one, even if it gives its owner a false sense of security. There is still non-zero utility there.