At this point, does it really matter if people are simply taking steps to hide their Facebook posts, or if they're starting to PGP sign their emails?
People are starting to do something; starting to feel that it's important enough to do something. That's a positive step, each subsequent story makes them think "Oh, maybe I should do this thing more often, or keep these posts private." That increases the overall digital literacy, for lack of a better term, with each subsequent generation doing better than the past. Most people now know not to emails from strangers with attachments, if not most then certainly a lot more than did 5 years ago. Same goes for password practices, people know they should do better at them regardless of if they do or not.
Eventually people will, or services will do it for them, encrypt their phones, they'll put a half decent password on things, etc. It's just not going to happen overnight. We should be encouraging any little steps people take, not deriding them for not doing enough.