As Schneier recently said, assume everything is vulnerable by default [1], and work with the machines having that in mind. Until everything from the hardware level to the OS and applications is open source (which is pretty much the way FSF has always told us it should be, because they feared the outcome we've already seen), we can't trust them, and even then we have to be very careful about bugs.
[1] - http://motherboard.vice.com/blog/an-interview-with-bruce-sch...