You got me thinking, dplax.... so I just checked the settings on my Linksys. And while other hardware firewalls may have protection for keeping things on the inside, I couldn't find a way in mine to be able to limit individual applications. I mean, I *could* limit them by port number, but there was no easy way I saw to be able to say that Firefox is allowed out while Safari is not. That's not a knock on Safari, BTW... I just don't run it, so if it wants out, something's wrong...
And yes, blind assumptions that a firewall (any firewall, HW or SW) will protect you against everything are foolish. As I'm fond of saying, locks are there to keep honest people honest. The more you have, the quicker someone is going to try to break into another computer since this one's too much work.
That being said, some people have nothing better to do than to try to break into a computer that seems to be well-hidden...