Become very familiar with the following two things:

GUID and SUID.

If configured properly, no one will be able to pwn you.

As already mentioned, be sure that you make separate partitions...