Personally, I've been doing quite a bit of security-hardening with my setup on Linux. I use Fedora Linux, I keep it up to date as much as I can (usually when Discover tells me it's a security update), and I've been following the playbook from https://secureblue.dev/ for further tweaks. I enabled Secure Boot in UEFI. I enabled IOMMU and Pre-Boot...