Well, but the recent fix to Java was to force the user to click through a prompt from the Java plugin itself; so once the user tells Firefox that yes, I want this dangerous content to run, they get another warning about dangerous content from Java.
If they manage to click through everything correctly and whitelist the site, they're good to go, but I suspect many of my users are going to get at least part of it wrong the first time through.
And of course, the noise about Java security is already breaking things -- for example, a few days ago I got an email from a teacher whose school paid me a $600 for a Java-applet based site subscription... at the same time as their IT department completely uninstalled Java from their school computers.
So now I either have to convince their IT department directly to re-install Java, or refund their money; whoops.