Sure, sandboxing all the individual components and not just the whole would help. That's not what was being suggested though, and is a significantly more complex and labor intensive task than even just fixing all the the included libraries to be more recent and not have known exploits (even thought it would pay dividends later). I wasn't dismissing sandboxing as an effective tool, just noting that it's likely not all that effective to put it all in one sandbox as suggested (and since actually fixing all the problems is likely a lot of work, it doesn't negate the effectiveness of the strategy of Signal by providing an easy solution to the problem).