I think you may be slightly biased here :). A security exploit that requires clicking is a lot less serious than one that happens without user intervention. Since <video> and <object>/<embed> can play automatically, it makes sense to limit the tags' exposure to unknown code from the operating system's installed codecs.