Here's the Microsoft URL:
<a href="https://www.microsoft.com/en-us/windowsforbusiness/windows10-secured-core-computers" rel="nofollow">https://www.microsoft.com/en-us/windowsforbusiness/windows10...</a><p>One part of this is <i>System Guard Secure Launch</i> which is documented at <a href="https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection" rel="nofollow">https://docs.microsoft.com/en-us/windows/security/threat-pro...</a><p>Unsurprisingly, TPM 2.0 is also part of the package.<p>Here's a really interesting tidbit:
<i>"Additionally, Windows monitors and restricts the functionality of potentially dangerous firmware through System Management Mode (SMM)."</i><p>Does this offer protection against malware that uses SMM as an attack vector? Or does this protection run as SMM?<p>In terms of features and protections, how does Secured-core compare to the state of the art in mobile devices and their locked bootloaders?<p>I wonder if Linux can take advantage of secured-core (or parts thereof)?<p>So many questions...