It looks like they changed their policy because the last time I tried to use them "legitimately" they required both Flash and Java (not javascript, but Sun's Java plugin).
As for banking data, even if it is encrypted it doesn't matter since it needs to be decrypted to be used. They get that data the same way your DSP dumper (presumably) does.
Except your very own site is designed so that you can't use something like adblock plus. As for breaking out of the VM, unless you do something stupid like share entire drives there are only two times that I know of that it was possible and only one of them would have actually worked. One used the floppy support and the other used 3d acceleration which is of course disabled (along with sound and USB). It is much harder to break out of a VM, especially with hardware VT support, than it is to create a flash exploit.
"I've added a basic anti-hotlinking system on the website, that means you'll not be anymore able to download releases from direct links or with adblock."