I don't want my computer to always be as closed and restrictive as an iPhone. That's good sometimes and perfect for some users, but not for everyone or all the time.
If the OS vendors are motivated to harvest peoples data, why on Earth would they be motivated to make sure nobody can harvest peoples data?
Also, some people use an iPad Pro connected to a USB hub connected to a monitor, keyboard, etc, as their daily driver.
Also, doesn't MacOS sandbox most apps?
Half the problem is that too many people rely on commercial software that will crap itself if it doesn't have access to what it wants whenever it wants. If, say, Adobe CC stops working after a new macOS release because macOS won't allow it to litter the filesystem any more, the one taking the heat won't be Adobe (which shouldn't have been doing that in the first place) but rather Apple.
As far as network control... We have open-source blacklists for various malicious websites. Perhaps we should also have "known-good" site whitelists and have OS-level blocking for that by default. Like, OSes running DNS-sinkholing of StevenBlack malware lists, and the option to enable "known-good" whitelists as well. Having a hosts file of 450,000 entries to sinkhole can bog down an interface coming up reliably... that process needs optimized.
There's a lot of money in the enterprise world doing similar things.