Yup, for most people, the thing that most needs protecting is the data, not the apps. But the important thing to note is that if the malware can't install itself/access hardware (esp. the network interface), then your platform is not very interesting for malware writers.
Of course, I should point out that the person you were replying to was exactly back-to-front. It's much easier to wrangle a privileges escalation than it is to get onto the system in the first place.
Yes but you have backups of that stuff. The real threat/pain is your machine becoming a spam/etc zombie without your knowledge. This is highly unlikely on any Unix-like OS.