1) This attack is not using 0-days. It's using vulnerabilities that have been in the wild for almost 6 months now, and are so trivial to exploit that some security researchers called the exploits "amaturish". These types of devices have been used to DDoS lots of internet infrastructure. What, short of something like this, is going to get those devices and their manufacturers to secure their hardware, given that Mirai wasn't enough to convince them?
2) I honestly think that finding/making a legal means for this sort of scan (specifically, scanning to check for trivially insecure devices, and bricking them if cannot be patched) to happen on a consistent basis is something that the EFF or the like might want to look into. The problem with a vigilantes is that they lack accountability, so while I might personally approve of the current approach from what I can see (even as I recognize it as illegal), it could take easily take a turn for the worse. I think having a standard around need to survive X number of hours connected to the internet and that a certain number of devices (say 10) need to survive 6/12/18/24 months down the road or face recall would be starting point. There are a lot of contingencies to work out for this, such as personal DIY projects and the like, it's not 100% fleshed out.
3) As far as I can tell, the analogy is more along the lines of a bunch people buying a bunch of stereos and/or loudspeakers that are trivially hackable (but the consumers aren't aware of that), and then putting them everywhere. If those loudspeakers and/or steroes started disturbing the peace, or getting used in ultrasonic attacks on power lines or water mains, you can bet that police would be destroying them, and/or allowing others to do the same.