> I would imagine that most users who bought a Mac want to run Mac OS, not any other OS.

yes, and it's unfortunate that Apple doesn't have a clearly published policy of how long they continue to support OS releases (and that they don't continue to release security updates for longer).

> You believe that a Mac with an old version of OS X, running with the OS X firewall enabled, behind a NAT router, not running any server programs, is vulnerable to attack from the Internet?

I believe that most people are not capable of safely running an internet connected device that isn't actively supported by a vendor.

The specifics of what must be done to mitigate the risk depends a lot on the specifics of the situation (and often would cost more than just getting a new box / installing a different OS).

