To some extent it's true though. If you want to do things the paranoid way, then Linux does offer you many more possibilities of protection.
For example setting up different profiles for social networks / banking / random browsing / ... and protecting them externally to the browser using selinux/tomoyo/apparmor/whatever-you-prefer (or even go full virt with qubes!) will give you much more security - no breakout on a random page will be able to touch your sensitive data. And it doesn't even matter what the browser exploit does.
Funny thing. I looked at my logs, and only today there were 6 attempts of getting into my computer, originating in different countries. And that's because the lamer ones don't get far enough to go into the logs.