(thanks and I agree with you, don't get the rest of my post wrong)
Air gapping is not feasible for situations like this in 2015 imo, I mean not for 'medium security' situations like this. For example you'd want to integrate it with the rest of a home automation system, which you'd want to integrate with various online services (weather data, calendars, ip cams, not to mention access from the outside & automatic upgrades). Of course you can build all sorts of 'more secure bridges' and all, but it's just a hobby, I don't want to turn this into a job to maintain - and for mainstream roll-out, such setups are even less feasible.
I mean I understand what you say, my point is that I think that we've moved beyond that - we need to assume for applications that are not life-or-death that they will be internet-connected, and in most situations we also need to assume that they're hostile; nobody can 'know' at any point in time what is really going on in their machines and on their networks in 2015 (again, in situations where you don't have whole teams whose 24/7 job it is to monitor and be proactive).
This seems in contrast with my original question of course :) , but I was more getting at novel approaches to 'security mitigation' - which is vague to the point of useless but that's because I don't even know how to begin solving this for our current age, hence my question. Much like 10 years ago nobody knew about the blockchain and its applications, and some problems that seemed impossible to solve (not just 'technically hard', but 'impossible') maybe aren't that 'impossible' any more now.
I've devolved into rambling and I'm not expecting that someone drops the Big Revelation of the 21st century into my lap in a HN comment either, of course, so I'll just stop typing now :)