> we are able to assess just how (in)secure an application is
Realistically, most people aren't going to do this. A more pragmatic solution is to use a minimal system, where for every task, you always use the smallest application that will perform it in an adequate manner. With proprietary software, you seldom get the ability to set up such a minimal system.
In particular, this means that I will never use a desktop environment, because there is no task for which a desktop environment is the smallest, simplest possible solution.