I recently had to deal with a rooted box where I only became aware of the problem because someone reported abuse from that machine on a bit of network I'm responsible for. Some of the tools on the box remained usable to verify and identify the problem.
(The real source of the problem was a legacy route to the net that is not as well configured and monitored as it should be. I can't wait to be able to turn that route off.)
I agree with q_q_anonymous here. Just because something is broken in principle, doesn't mean that it will always be broken in practice. Policy, of course, should be designed around knowing what is broken in principle, but that is part of the concern for costs and risks one is willing to bear.
I'm not a big fan of these "personal firewalls", and it can be argued that they cause more harm than good (by giving admins a false confidence), but that point has to be argued. It can't just be declared.
In practice, if someone had a machine directly connected to the Internet with no NATing or other network firewall device between it and the big bad world, I would be jumping up and down saying things like ZoneAlarm are not good enough. I would insist (depending on my influence in the matter) that they get some other device. But that is different from saying that PFWs are entirely pointless. All it's saying is that they can't be relied upon to do a job that I think needs to be done.
-j