'Transacting' requires not only identity but accountability, a completely controlled-by-you phone cannot meaningfully transact separately from you.
I feel like a lot of new security concerns would be created.
Problem with sandboxes is that it doesn't solve the "user who doesn't know or care" problem.
If you have to give access to particular files to an app, your average user will just give access to all. Someone installing tiktok doesn't look at the permissions...
The best thing would be for apps to operate on their own copy of a file regardless. But that doesn't stop bad apps from leaking importsnt files. Unless files can be signed as being for x thing requiring y special permissions as granted by the originator and not the user.
The crowd on here we can't to be able to truly own our devices. But I think for the safety of the average person they should be locked down by default, same as dev mode on android devices where you accept liability for doing silly things.
(Yes reworking our all our systems in terms of capability security is a giant job. But there's a difference between a giant job and )
I didn't submit this! Happy to chat about it, but I feel like I was pretty clear in the post that I wasn't bidding for the front page.