They did "screw up", i.e., the financial side of the business thought it was ok to hurt the user experience in order to make more money, and the engineering side was too incompetent to realize the security risk. Why would this level of demonstrated incompetence lead you to believe that they will be better in the future?
There's also that this particular kind of compromise is basically inapplicable to hardware. What are they going to do, put a 3G radio in your laptop that broadcasts your "data" via the cell network to Belarus?
http://thehackernews.com/2015/02/hard-drive-firmware-hacking...
So no, they'll get a rootkit process running on your machine and (for instance) upload everything on your hard drive through your web browser.
Another thing they've done is to upload hacked drivers to cause other hardware connected to the infected machine to physically destroy itself.
Is that spyware Windows-specific?