I saw
this post the other day on the IE team's blog while looking at some
IE7 stuff...
I was unaware that the SV1 token gets added to your browser User Agent string after XP SP2. I don't think in this case it matters if SP2 is more secure than RTM XP, I still don't want someone to know my patch level. Call me paranoid...
As fortune would have it,
fiddler has an answer! Thanks

Oh, with regard to IE7 - apart from all the user experience enhancements like tabs (thanks for coming to the party IE) etc the killer I reckon is in protected mode registry virtualization - I think we will see more of this in future!