The first paragraph of the conclusion begins with: "“Given a choice between dancing pigs and security, users will pick dancing pigs every time.” While amusing, this is unfair: users are never offered security, either on its own or as an alternative to anything else."
User do get offer security in many ways: red web pages warning of an unsecure redirect, open lock icons on the address bar, etc. But the dancing pigs will be more amusing until the user understand the underlying concept of the warnings. Security must begin with education. Kindergarden level education.
The last paragraph of the conclusion ends with: "How did we manage to get things so wrong? In speaking of worst-case rather than average harm we have enormously exaggerated the value of advice. In evaluating advice solely on benefit we have implicitly valued user time and effort at zero."
My point is that part of the answer should be making things understandable. Making things understandable to everybody will reduce the cost of dealing with them.
The reality is I had an argument about why we should be writing down passwords at work, because the projected security benefit of preventing a full breach is still less than the expected benefit of not losing our data all the time.
Could we have set up a better, more technical PKI than notes in the safe? Probably. But I'm not sure it would get us ahead on the cost/benefit curve.
Real security is about separating your porn watching from your banking; not about doing your porn watching to the security standards of your banking.
tl;dr: No, dancing pigs are always more amusing. No one wants to live in a perfectly safe box.
My argument talks about motivation, not implementation.
This is tough, as most talking points discuss the worst case cost for someone ignoring security. The normal cost for ignoring security is much much lower.