Even a sophisticated user is just as vulnerable in many cases. If I give personal information to a third party site that I presume to be trustworthy (say a government site) there's no way I can know if someone is going to find SQLi vulnerabilities in that site next week and exfiltrate all of that data.
SQLi should not be a thing. At all. It's the most trivial fucking thing in the world to validate data before you use it in an SQL query, and people get it wrong, every single day. Security isn't hard, it's just tedious.
That's just the way the Internet is right now.
Sure, there's evolving threats, there's drive-bys that will slip around all of this, there's ways attackers could still get through. But as scary as it all is, anything beyond these steps gets into the territory of major inconvenience. The problem with that is, the more intrusive and inconvenient the security becomes, the less likely people are going to be to actually use and remember their security practices. If mom can't repeat it at her book club, it's not going to be effective. And to be honest, these types of attacks that bypass these restrictions are exceedingly rare when it comes to mom and grandma. The biggest threat there is phishing and malware. Corporate security has professionals enforcing a policy that meets the business's own requirements.
So to answer your question, yes, that's all you can reasonably do. In most cases, you'll be pretty well protected with just that, and those steps aren't too complicated to follow or remember.
Turn the computer off when you're not using it.
If I look at the logs, it's all connections to CDNs with weird hostnames. How do I know which ones are legit and which ones might be part of a DDOS?
Also CC numbers are 16 bytes long, would just get lost in all the noise..
The internet is not safe for banking, and I don't see any way it can be made safe.
Have you noticed the spate of attacks against SSL lately? BEAST, CRIME, Lucky 13, RC4 in general? https://en.wikipedia.org/wiki/BEAST_%28computer_security%29#... Not profitable for some things, maybe, but definitely worth mounting such an attack for banking info.
Have you noticed that the certificate authority system is totally broken? http://www.theregister.co.uk/2011/04/11/state_of_ssl_analysi... Heard of DigiNotar? Comodo? http://arstechnica.com/security/2011/09/comodo-hacker-i-hack... These aren't hypothetical attacks! Google got MITM'd by Iran https://blog.mozilla.org/security/2011/08/29/fraudulent-goog...
Most people's personal finance is probably safe to do on the Internet because of legal requirements on banks. Small businesses are another matter.