You make valid points. But for years malicious Flash applets were one of the primary ways malware was delivered over the web. For IT departments, unless a user absolutely needed it, it was removed from their system. There was a time where it seemed like there were new critical vulnerabilities in Flash every week, and it was a nightmare to keep up with. Security, or lack thereof, contributed greatly to its demise.