Okay, let me post some information for the masses based on my 30 years of IT experience:
Order of best mainstream operating systems based on both privacy and security risks:
- Linux
- MacOS
- Android OS
- Mac iOS
- Windows XP
- Windows 7
- Windows 8 & 8.1
- Windows 10 and higher
Now, the Android and Mac iOS systems are pretty secure as operating systems, but cellular carriers usually add their own crap on top of the OS that sends information back to the carrier without the user's knowledge. Beyond that, where people get in the biggest trouble is with the apps they install. My advice: Don't install any app you don't absolutely need. As for games, only install games that do not require network access to function and block their network permissions.
Personally, none of my devices: laptops, phones, tablets, etc. are allowed network access until I've installed a firewall that gives me full control over every app's ability to communicate with the outside world. I realize that your average user doesn't have the knowledge necessary to do this for themselves, but I say this to illustrate just how bad having these devices can really be. My latest phone wasn't even activated until I had wiped the factory-installed OS and installed one that is more secure. Even my Linux laptop, as secure as the operating system is, has its own firewall installed. On top of all that, my home network is fully protected by a linux-based network security platform that gives me full control over every single byte of data that enters or leaves my home network. Again, beyond most average users' capabilities, but also to emphasize just how dangerous the wide-open internet is.
IoT Devices: In my professional opinion, the "Internet of Things" is the most prevalent threat to both personal privacy and global network security in the history of the internet. For those who don't know, IoT devices are items like thermostats, alarm systems, Ring doorbells, smart TVs, garage door openers, Roombas, smart light bulbs, home assistants like Alexis and Cortana, even kitchen appliances. All of these "smart" devices are capable of connecting to your home network, at which point two things happen:
- They can send information to god-knows-who
- They are vulnerable to attack and being compromised by anyone in the world
IoT devices are notorious for poor security, and security patches for vulnerabilities that are found later are hardly ever issued by the OEM. And yes, there are people out there who do nothing except probe for vulnerabilities in this stuff.
Two examples from my own home network:
We have a smart TV manufactured by Samsung in our bedroom. We use it to watch local news in the mornings before we get out of bed. It also has a wireless connection to my network so we can watch Netflix or Hulu on it. Now, the first time I turned it on and connected it to my network, my network firewall lit up like a Christmas tree with all the data it was trying to send to Samsung and Amazon. Even when just watching plain old television broadcasts, it tries to send out data over the internet, which my firewall blocks, except for Netflix and Hulu.
I recently installed two GE smart bulbs in my home office so I could control color and brightness. This ONLY works through an app on my phone. Sure enough, the second they connected to my home network, the firewall started blocking hundreds of data requests being sent to Google servers. Now, I lose some functionality by blocking all that traffic, but the basic functions are still accessible.
Can you imagine an average user who knows nothing about network security and is either ignorant or apathetic of the risks that are out there installing all of this stuff in their homes without any security at all???? Hell, our Roomba has a floor plan of our house stored in its system for christ's sake! It tries to phone home all the time!
Newer cars are coming from the factory with a two-way OBDC system that utilizes bluetooth and/or wireless technology to communicate. This means they can be hacked by someone in a nearby car who can then take over any vehicle functions controlled by computer. This isn't theory or the stuff of Hollywood; this has actually been proven in real life testing.
Everyone remembers how SkyNet existed in hundreds of thousands of computers all over the globe, and that's how it was able to take over the world's technology so quickly? That's not science fiction. "Bot farms" consist of hundreds to hundreds of thousands of compromised devices which are then used in a coordinated attack against one or more selected targets. The more compromised computers on the network, the more effective the attack. I can guarantee you there are computers, phones, and even thermostats sitting out there right now that have already been compromised but are continuing to function normally while just awaiting the command to execute whatever attack they've been programmed to carry out. And when - not if - it happens, people are going to have the nerve to act surprised.
Cell phones and computers are dangerous if not used responsibly. If you believe nothing else I have to say on this board, believe me on this, because I have witnessed it first hand and have been defending corporate networks against literally millions of threats for several years. Part of the reason I switched careers recently was because keeping networks safe is becoming next to impossible, and I wanted out before anything major happened. And when it does, on my home network firewall there is a special configuration setting that I have never used except in testing. It's labeled "Emergency Network Isolation." Essentially, with a single mouse click I can kill all inbound and outbound traffic on our home network. It's designed to be used in the event of a major cyber attack against the United States. Then I will fire up a special laptop I keep offline that is specifically designed to function in a high-risk network environment so that I can safely monitor the situation without risking being compromised.
This isn't paranoia. This is how bad it really is.