I hope to god I'm never a valuable enough target to use a zero-day on. Posting here is probably the closest I've ever come to it. There's really no defense I've found that doesn't cost more than I can afford or inconvenience to the point of unusability, so I just operate under the assumption that one day all encryption will be broken and everything I've ever typed online will be visible to anyone who cares to look.
That's probably almost entirely justifications to make me feel better about the reality of the situation, but it is what it is. In the meantime, antivirus is an adequate defense against more common threats.
For people who are a valuable target, though, you're absolutely right. Block everything but the essential data and use every obfuscation possible. Nothing else is any protection if someone with the means has it out for you.