Rich Mogull over at Securosis totally nailed it. This article he put up talking about the Web Application Firewall (although it's still a mis-named product, see my rant here ) vs. secure coding is brilliant. I've been saying this since I can remember...