If you're into tilting at windmills: I have run my browser with 
flash turned off for years. I read the rate of serious security 
bugs in flash, and it is worse that IE in a bad month. The 
result is that until utube went to HTML5, I couldn't see any of 
the videos people linked in their emails. Oh well. I don't 
generally go to movies either. YMMV

I could see an organization being hard nosed about the 
situation. Put up a browser which only supports a limited suite 
of protocols, based on a security analysis. Use it on the 
internal network, with no access to an external network (via 
firewall perhaps) so your operators can't upgrade it to run 
things like flash. (And fire them if they try.) (If they want to 
watch movies, let them use their phones.) Specify in your RFPs 
for equipment that the management interfaces for that equipment 
must run with a browser that only supports the listed protocols. 
Even a failed attempt, if well publicized, might push the 
industry in the right direction.

