I'm still on SP1 and all I do to protect myself if the occasional (monthly, if that) AVG / Spybot scan. I have no firewall (use a router). I use firefox for the web. I've had no trouble whatsoever, so I don't see a need to bloat my XP some more and SP2 it. I've noticed though that elements of it have
seeped through thanks to the automatic updates I install.
I see SP2 more of something Microsoft released when they realised a whole lot of windows users are generally complete novices when it comes to computers.
I don't want my XP trying to lead me around by the hand any more than it already does.
Jam it back in, in the dark.