<<Yeah, but if the firewall has been in place since the attachment to the 'net then, theoretically, all the out-going request should be authorized/initiated by the user, right?>>
Theoretically you are correct, but in reality people don't start with a blank slate. The system may already be compromised and therefore, with BID installed, will never be aware of the problem.
Worse still is the fact that there are certain trojans and virii that can get into your system without triggering a reaction from anti-virus programs. Some javaspript virii get in that way and cause problems.
The point is that outbound requests need to be monitored.
PCWorld keeps giving Zone Alarm the award for best PC firewall product.