No, what we did was trade off one set of security problems to having dozens of clients for every TCP protocol (IRC, NNTP, SMTP, IMAP, FTP, WAIS, Gopher, fingerd, etc) with their own set of security flaws, but which had less oversight, and that gets you things like the Morris worm.
And because every one of these had their own rigorous protocol, and their own binary clients, if there was a flaw in the protocol itself, it could take ages to get a fix to the protocol from the IETF and all clients deployed with the fixes.
So for example, the obvious and horrible security of usenet led to the first massive spam bots, which then led to a bunch of even more horrible mitigations like Cancelbots, which led to a bunch of counter-mitigations like Resurrector-bots.
These days, with ephemeral, mobile code, a security hole in the client/server protocol of a particular app can be fixed in an instant and rolled out to everyone. And the Web is better at this than the native mobile or desktop platforms, now behind curated App Stores, with a lower update frequency, and whose very closed-source curation process means they don't get as much rigorous testing as the Web in running untrusted code.
The Web has been running untrusted global scale mobile code for decades now, and most of the exploits on the Web have occurred as a result of bad server programming, not holes in Javascript. So Web 1.0 request/response apps won't save you, all it will do is punish everyone with bad latency and higher server loads.