Conversation

Summarizing Windows 11 Security Announcements: Pluton SHIPPING HVCI/VBS on default ALL CPUs Credguard default ON LSASS Protection default ON EXE signed or rep REQUIRED Script Blocking from Internet ON Enhanced Phishing ON File Layer Encryption with Hello ON
25
445
does it have any code execution features? I always wished I was able to give a custom algorithm to store with a secret. Would let one implement traditional TOTP and similar
I assume you mean VBS enclaves. Unfortunate, they're quite a bit less usable for Linux unless it's Azure. Also a bit weaker as the raw secret must leave the TPM, not just generated stuff in there.