I’d use macOS. Application sandboxing, per directory access controls, signed read only root, xprotect and gatekeeper - security out of the box on common linux OSes is a joke compared to modern macOS.
Good points, especially about sandboxing.
Good points, especially about sandboxing.