The everyday citizen is not computer savvy enough to know that the NSA is spying on them or that Windows needs regular security updates and antivirus updates, and that they need to pick a different password than 'password' for their account.
Most of them work a job for a greedy employer who gives them a Microsoft Windows PC locked down without administrative access with just the software they need to get their job done. No operating system updates or AV updates for three years and since they don't have admin access they cannot run them. They are stuck with an older Internet Explorer and cannot install a third party web browser that would be more secure and have less exploits and use Adblock or NoScript.
Most likely they use XP/Vista/7 in order to run some legacy Windows software, and management does not care about security and has fired all of the competent and experienced IT staff to hire college and high school dropouts to work for a bit over minimum wage to save money and maybe some H1b Visa workers.
For the everyday citizen I just point them to this site:
https://prism-break.org/en/
But it is completely over their heads to understand it or how to install apps in Windows or even boot a Live Linux CD, and at work their PC is locked down and even if they knew how to do all of that, management would fire them if they did it because management sees making things secure as a waste of productivity.
Sure a lot of companies that post at Hacker News here are not everyday citizens, but experienced and competent IT workers and hackers who know security and most likely boot a version of GNU/Linux with the privacy programs already installed. The everyday citizens does not even read HN, because 'Eek hackers, they might give me a virus infection and steal my email account!' because the everyday person is told that 'hackers will infect you with a virus and steal all your data' and then point to an article about Target's POS systems being hacked by viruses, etc.
Nope those are 'crackers' and 'black hat' people. 'hackers' on hacker news are 'white hat' people who actually build useful software and operating systems and help people out. Then give you useful advice on security.
Even the federal government does not get computer security:
http://blogs.computerworld.com/malware-and-vulnerabilities/2...
Most US corporations and colleges and universities have the same problem as the federal government. They fired anyone who was competent enough to implement a good security policy, and they went with an insecure security policy because it was easier to implement for the everyday person to be able to use their Microsoft Windows PC systems.
Heck I've been to some startup dotcom hackathons where they had very poor security and only focused on writing code and storing it on a server with a weak password of 'password' and overloaded the electrical outlets with a couple traps per outlet to power all of the PCs they used to write their code. Violating the fire code, weak security, virus infections, and nobody seemed to care as long as they had the potential to make some new IP and earn some money.