2albator: I deployed SP2 to more than 2000 machines. It is best SP/FP ever. And the real true is SP2 is great for home users AND for domain administrators. What do you understand under "real" firewall? Show me any firewall with domain/standart policies, boot time protection, safe lockdown mode and compatibility with GP? There are only few - Absolute Firewall and CyberArmor. Do you know that 60% of people that uninstalled any FW said it was because it was annoying to unblock outcoming communications? That is why MS included only incoming traffic and it was right choice. About Bruce Schneier, this sentence was quite catastrofic to his "professional" look - applications are not working because they included bugs, that SP2 reveiled, like anonymous DCOM calling and similar. And I really appreciated that MS said they also had buggy software and patched it rather than leaving the holes. Services? You mean essential changes like dividing RPC to two (local and network) services? The stuff CSO all around the world was calling for? Or you mean DEP protection? Network limit is one of the most favourite hoaxes all around the internet - it is limit for UNCOMPLETED TCP HANDSHAKE, it is not system-wide limit! So the only stuff it is blocking is speed of P2P, scanning tools and MOSTLY viruses. Dont change nothing to IE??? Most changes were made to IE - like binary behaviors and what is most important, finally they tried (successfuly) to solve IZ0 (Local Machine) problems... "Minor" changes like windows restrictions are just the bonus. Just have a look at Secunia - last two months only one exploit for IE, but 7 for FireFox - or you could have a look at today bugtraq - two for FF, 0 for IE. About "Your about to run a .exe this could bla bla bla " - this IS NOT the support message. This is much more important change, because it is message from AES and it means that applications like OE, Messenger or IE will be much safer.