Everything at the lowest levels needs to be tightened up now. Buffer overflows in trusted code have to go. This means getting rid of the languages with buffer overflow problems. Mostly C and C++. Fortunately we have Go and Rust, plus all the semi-interpreted languages, now, and can do it. We need something that runs Docker-like containers and, all the way down the bare metal, has no unsafe code. We need dumber server…
If you fix the software, the NSA will just backdoor the firmare/hardware (if they haven't already) and, even on an Android phone running AOSP, there are literally still millions of lines of proprietary, unaudited, closed-source code. Not to mention half dozen microprocessors containing circuitry you can't possible inspect. PCs are the same these days. Do you really expect these multi-billion $ industries to change? There's only a niche commercial interest for consumers of 'simple and well-understood'(read: secure) firmware.
And it's not like the hardware/consumer industry is sitting pretty as a lone miserable failure from a security sensitive standpoint. Then entire Internet stack from Ethernet and BGP up the way up to HTTP is complete and utter garbage. Our standards bodies (IETF, W3C etc) are failing to protect us and there's no sign of it getting better because the cost of starting over is simply too damn high.