Actually that's true. I ran a machine with no AV for eight years just by disabling JavaScript, using a hardwired firewall, being careful and occasionally using online scans.

Also surfing with a user account with minimal permissions.