absolutely correct BigChimp, firebird should be behind the DMZ, firebird in that sense has not the most secure login structure.
I have used this model myself, and once you have the middle bridge running you can connect anything that supports http protocol, including legacy mobile devices.
Just as a info:
I have actually only two commands.
1. SQL_QUERY that returns a xml data packet
2. SQL_EXECUTE which is for sql statement that don't return a dataset
Plus a very simple error checking. which returns SQL_OK or SQL_ERROR and the message.
works perfect, and the main advantage is you don't have to distribute any client software.