Personally, I've been doing quite a bit of security-hardening with my setup on Linux. I use Fedora Linux, I keep it up to date as much as I can (usually when Discover tells me it's a security update), and I've been following the playbook from https://secureblue.dev/ for further tweaks. I enabled Secure Boot in UEFI. I enabled IOMMU and Pre-Boot DMA protection. For the most part, every supported feature in my board is green on
fwupgmgr security with the only one that's red that isn't something I couldn't find in my BIOS being "Platform Secure Boot" and I suspect that is because I chose to enroll the Ventoy Secure Boot key. I'm running SELinux in enforcing mode, I blacklisted the modules that Dirty Frag exploited prior to it getting patched, and I took some sysctls from this config, specifically disabling kexec and io_uring. I'll be testing more of these and seeing if they are worth it. I use SecureBlue's browser as well, Trivalent, on Fedora.I know some are very old-school "common sense is your best security", and I used to be like that. I thought I would be good just by ignoring sketchy links. But I do feel like doing more for your security profile is generally better.
EDIT: I also explicitly avoid NPM, I masked sshd and block SSH on my firewall, and only have a few ports open that I explicitly chose to open.
https://redd.it/1uajq0k
@r_linux