> Is it, really? You're still supporting DRM, because that's the basic requirement here. You're still therefore running unknown, closed source code that is prima facie working against your interests as a user.
On far, far less websites, however. One or two video streaming services have DRM. Banner ads in most pages will not be using EME.
> You still have an extra potential attack vector for malware.
This is true, but one with a smaller surface area. One that might not even be installed, in many cases.
> Flash on phones only really lasted for about two years, and given that the earliest phones somewhere around 2010 were running something like 1GHz low-power processors, it's not entirely surprising that the initial performance wasn't great.
1GHz is slow, now? Wow, Flash must have sucked even more than I thought.
> Various video hosting sites that had been reported to perform badly in earlier criticism were debunked, with evidence that the other junk on the sites was causing more of a problem than the Flash video itself and that similar Flash videos could play just fine on devices of the 2011-2012 era. Likewise claims that Flash seriously reduced battery life didn't stand up to careful scrutiny over several days of investigation in some cases; battery life was generally found to be reduced, by sometimes by no more than a few minutes.
Links? I'd be highly sceptical of this claim: software video decoding is not good for battery life, for example. Of course if it's H.264 I'm sure Flash would use the hardware support, but why would you use Flash in that case?
> When did Flash ever run on the iPhone?
Never, but I mean by the time that the iPhone was powerful enough that getting Flash to run on it might be reasonable.
> Given the number of sites I run into that still don't work properly on an iPad, I have to disagree.
Most of the web has moved on. There are still plenty of sites that don't work with mobile devices and require plugin downloads to be used modern browsers, it's true, but it's a number that is continually decreasing.
> Because I have concerns beyond just security. I don't run a browser so I can be secure. I run a browser so I can browse. When you take security so far that you break the basic functionality of your system, you aren't so much securing it as... breaking the basic functionality of your system.
Flash support isn't "basic functionality". It's a bonus. Mobile devices can't and shouldn't support browsing every website made for a PC in existence, they just need to support most reasonably well, and that they do. After all, PCs still exist.
Mobile devices also don't support simulating right-clicks, Java applets, the Unity web player, ActiveX controls, and so on.
> In any case, with the new model using media extensions, we still will be adding binary blobs to the browser,
Smaller ones with much more limited scope, used in far less places, and which you can blacklist without breaking a lot of websites.