One better than what ? Sandboxing has been around for decades. It's not a novel concept. BSD Jails ? HP-UX SRPs ? Solaris Zones ? Heck, plain old chroot jails ?
Welcome to yesterday's security measures.
Some times you don't have to reinvent the wheel, you just have to implement it in the right way.
Again though, it shouldn't be an issue as this is only for MAS apps. Developers can still use every avenue that existed prior to the MAS, right?