not having a sandbox is less of a problem when you run FLOSS (in the context of PPAs that's relevant i think)
I disagree. Source auditing is irrelevant for day-to-day software use.