Compared to a Linux distro, would an end user have much better security out-of-the box, or would one need to be tech-savvy enough for that?
A lot of the security of the default install comes from minimizing the attack surface by having very few services running. So you do not need to be tech-savvy to make it secure, but you might need to be tech-savvy to turn it into a usable system for your use case.
mail, web, routing, tunnels, bgp, dns, hell there is even an ldap server in there for some reason. but no ldap client, which kind of sucks.