Yup you summed it up just about right there!! no need for SP2 what so ever!
Yes, the windows security firewall is a joke...but is adequade for most home users. You say real hackers can get past it, well duh. But real hackers target companies and people with important info. For the average home user, getting their comp hacked is annoyance and so this firewall generally protects against these small annoyances.
However, companies will use enterprise firewalls and etc. because hacking is more than an annoyance for them.
In addition, SP2 fixes a lot of security holes in windows. And just so you know, the win firewall is there to prevent against future holes, not to patch existing ones.
And just so you know, I think the windows firewall is just fine. Its the only software firewall I use and I've never had a problem.