That a cross-platform application distribution platform might have arisen anyway is beside the point. It'd have been nice to keep that separate from the locked-down hypertext platform that keeps the user in control. We've lost the latter in gaining the former, rather than having both.
[EDIT] I'm with you on humans being the problem over technology in general, but in this particular case I think there were technical reasons that Web 1.0 was destroyed in the creation of Web 2.0 and we were left with one crappy platform that constantly betrays and tricks its users rather than two, at least one of which isn't capable of betraying its users the way this one does. We're where we are because no-one treated Javascript (or anything else with its capabilities and liberties in the browser) as the fundamentally terrible idea and permanent trust-ruiner that it was. It's inherently and unavoidably a security disaster for the Web, not in terms of secure communication between client and server or whatever, but in terms of practical personal security for the users and their data.