Let's give more valid options:
1. Open source software with auto updates turned off (eg. Browser extensions like Alby)
2. Open source with updates off like apps from fdroid.
3. Hardware signing devices like Ben arcs esp32 device.
4. Nostr nsecbunker on a 247 server.
1 and 2 are objectively riskier than 3 and 4 because 3 and 4 are more likely to have your nsec stored on a device with less consumer grade software and less casual and social activities performed on them making them less likely to receive malware and viruses.