As the author of OLPC's circa-2007 "rainbow" uid-based sandboxing system (see http://sandboxing.org), uid-based sandboxing works reasonably well at the level of the kernel but interacts poorly with current free software desktops and is only questionably useful against adaptive adversaries given the rate at which new local privilege escalation attacks are discovered.