Good example because all that code is indeed run sandboxed, which is exactly what we need in native apps as well. "Any website" cannot access anything on my computer without explicit and often temporary permission.