of course, but, what if
1. the client turned off javascript or
2. her browser did not support javascript or
3. someone copied your form and got rid of the validation code but still submitted the data to your asp file or
4. your validation was ok on the client side, but some hacker modified the data on the wire?