A debian style update mechanism could solve this, but this would be really bandwidth expensive.
This is a good thing to remember, but I'm not sure it undermines the parent's point. No matter what security you use for anything, you always are exposed to another threat; that doesn't make all security useless. The value of security is to make attacks more difficult.
A government agency doesn't need to pay anything, they could use legal means to extract the information.
I don't think there's anything stopping plug-ins from sending unique IDs. SafeBrowsing uses a cookie that makes up a unqiue ID. (The latter discussion is well documented in Mozilla's Bugzilla)
But what tracking information would make your privacy toast? Privacy has levels. SafeBrowsing leaks your WAN IP to Google. (You already leak this to every site you visit) Plug-ins likely leak details about the plugin configuration (as Ghostery does). What's the value there?