Eeeek!
I admit, I may not have read all of the material here however my knee jerk reaction is not only "eeek" but this to:
MS keep adopting thier own standards especially where CSS is concerned. This does my head in since what with the Disability and Discrimation Act us web guys have to try and cater for everyone with most types of browser. Evolving CSS from MS usually means increased development cost. Also the W3C/WCAG followers will be a bit annoyed!
Personally I feel that user awareness and robust web applications are more of a security issue than the pesky browser.
For example, it doesn't matter what browser u have since I can still inject code into websites since this type of attack is on the server side, not really the client side. The only workaround I could foresee is if the browser itself filtered out POST HTTP traffic so that code (Vb/javascript/hex encodings/and SQL) never got to the server. This would no doubt cause all sorts of problems in so many ways.
Regarding the user awareness there's so many ways to dupe a user its scary!
A move in the right direction maybe but surely owners of web content should have a responsibility.
I'm all for spyware built in however there is a massive industry around spyware. MS surely can't blast that away. Personally I'm expecting MS's efforts to be much like thier so-called "firewall"... i.e. half a job that inspires user confidence incorrectly. Surely this is more dangerous?
Ok rant over

S