Ah... Figured # 2 out. ASP.Net is trying to protect me from myself (and injection exploits).

To fix, I added <%@ Page validateRequest="false" %>.

# 1 is still confusing me though...