Same as with any platform:
1) You account is regular user, not one with elevated permissions
2) Keep system up to date
3) Use the most secure browser for the platform
4) Don't use Java or Flash on such browser (or plugins/extensions, as a matter of fact)
5) Know what you visit and use common sense
Never had a virus/spyware on Linux, OS X or Windows.