Agree, users are a good start, also systemd for example provide ways to run a process on its own file system too, readonly, etc... I guess virtualization or containers is needed because of the unknowns bugs, bad use of technology and /or not being able to harness a system very well with non sandboxing methods.