One approach to this is to build new tools and components that incorporate security & privacy by design. Discarding elements that are not required for a particular use case is also beneficial as there's less a hacker can do if they do manage to get in.
These approaches are captured in ideas behind unikernels, such as MirageOS [1], which themselves can be part of a larger stack [2]. I work on both of these and we even put together a contest (Bitcoin Piñata) to incentive a search for weak spots (and a bit of fun) [3]. I honestly think that only new software stacks or government regulations can fix these issues. Given mass-surveillance, I don't hold out much hope for the latter.
[1] http://mirage.io
[2] http://amirchaudhry.com/brewing-miso-to-serve-nymote/
[3] http://amirchaudhry.com/bitcoin-pinata/ and https://news.ycombinator.com/item?id=9027743