“We just need to educate users about passwords” “We just need to educate users about how to verify SSL certificates” “We just need to educate users about how to install only software from trusted publishers” etc.
This reaction is understandable but it's a non-starter if we ever want to make meaningful progress on security. The underlying problem here is that everything local was assumed to be trustworthy and that's not true and, thanks to reflashable firmware, not even something which can be assumed to stay true even if it happens to be the case when you start.
Fixing problems like this will require changes – X-Istence mentioned OS prompting for new device classes, which would particularly effective on devices like laptops (i.e. the default for most users) which could require confirmation on the built-in hardware any time an external device tries to duplicate built-in functionality (keyboard, mouse, network, etc.), but we probably need more ambitious measures like adding a public-key exchange for certain device classes or a hardware switch which controls whether a port is allowed to control the computer or provide block storage but not both.
The one thing which is certain is that the .gov / .mil security people who seal ports with epoxy aren't looking as paranoid these days…