This is such a naive view on computer security. It’s not just about spyware, which is also not exclusive to commercial vendors.
What else is this about? Debian repositories still contain no malware and if you install software exclusively from them, you'll be safe.
It's not, though. There simply wasn't enough malware to worry about. Why would I run a firewall when I was unlikely to ever encounter a malicious program?