a) disable flash
b) disable java
c) disable any plugins really.
d) use chrome (at least)
e) do not allow downloading of any file. Instead use chrome's plugin to open any word/etc files in google docs.
f) Use a chromebook. Chromebooks can't really execute programs like windows machines can, so it's fairly safe. And worst case is you expose a sandbox machine with no private data other than caches, that can be set to be cleared on sleep or whatever. Bonus security points:
- if a chromebook is hijacked, it will only be hijacked until a reboot during which time the chromebook does a sanity check ensuring the OS is exactly intact. If it is not it just reinstalls the OS from ROM. Basically no long-term compromised machines.
- The only time chrome's sandbox was ever completely bypassed allowing arbitrary code execution was using a combination of multiple chrome exploits (now closed) and a windows data execution prevention bug. That can't happen on linux (and the chrome team works to further solidify that sandbox). Pretty much almost impossible. And if it is quickly patched and vuala.
g) browse in private browsing mode only
h) When visiting links (like facebook) manually type in the url to ensure nothing is spoofed.
I think you will be fairly safe. However... I doubt most people will go that far.