Unpopular opinion: "regular users" are, by their very nature, incapable of using any networked operating system with a 100% certainty of not infecting themselves with malware.
They're not qualified to only make safe decisions during their computing because they're not educated enough to understand what makes any given action safe or unsafe.
Using a computer is fundamentally not like using a car. Using a car, by and large, does not change. The only major exceptions are when the user fails to properly maintain it, altering weather conditions, and altering traffic conditions.
Once a driver has driven in any given permutation of traffic condition and weather condition, as long as they've maintained their vehicle, the driver's experience will be almost identical when they find themselves in that same permutation of conditions again.
This consistency allows drivers to build experience in adjusting their driving to operate in those conditions, which makes them better at it in those same conditions in the future.
We let laypeople drive, even those who haven't the slightest idea of how their braking system works mechanically, because there is an extremely limited range of outcomes from pressing the brake pedal at a given pressure in a given set of conditions provided it's maintained.
The scope of inputs we give drivers is ultimately tiny.
Computers are not like this. The safety habits you learned in 1995 are not going to cover every threat you encounter in 2005, the safety habits you learn in 2005 won't cover every threat in 2015, and likewise from 2015 to 2025.
As long as we give users a broad range of possible inputs, they will find ways to screw themselves with their own incompetence.
The reason iPhones and Mac OS computers are perceived by the layperson to be more secure isn't that they're inherently less hackable, it's because they treat the average user like the moron that the average user actually is by substantially restricting the input freedoms of that user. How many millions of iPhone users didn't get hacked because the developer denied them the freedom to sideload aribtrary unsigned IPA's
With great freedom comes an increased responsibility to understand the consequences of one's own actions. Users are lazy. Many are stupid. They do not read very much of anything. They do not understand the systems they are using and they don't want to.
As a technologist, I love having the freedom of an unbridled OS that lets me do whatever I want, including deleting the whole file system. That kind of freedom just isn't optimal for a typical user's security.
This may sound misanthropic to you, but look no further than the scores of people who microwaved or soaked their iphones because 4chan made spoofed ads that looked like real apple ads promising software updates that made it possible to charge one's iphone by microwaving it or a software update enabling waterproofing.
Users really are that stupid, and will ultimately find ways to harm themselves and their devices any way you allow them to, so long as there's a competent adversary trying to get them to do it.