Can you tell us what happens on the "sandbox all the things" goal?
I think this is a pretty crucial step forward, even though #sandbox technologies (most often through user namespaces) are more problematic than I initially thought.
As far as I understood, sandboxing needs to happen in #userspace, with tools like #fuse doing the work while being restricted by #MAC like #SELinux or Apparmor.
@kde@floss.social@kde@lemmy.kde.social KDE used to be my frontend of choice, but I really dislike how inconsistent it is across apps, specifically window frames that look different and have different buttons to manipulate them. GNOME doesn't seem to have that issue or at least isn't as visible.