Thanks, that thread made for interesting reading.  I've posted a reply:
http://weblog.rubyonrails.com/archives/2004/12/31/escaping-java-but-not-its-thinking/#comment-287