@inference @safiuddinkhan@fosstodon.org @cyberspook @iska@mstdn.starnix.network @dushman What's with the TPM 2.0 requirement of Windows then? Is it to verify bootloader only? I don't think so.
They've made it mandatory in Windows 11 only, but it was there way earlier than that.
Verified boot locks the root FS as read-only, so malware and corruption cannot persist. It is restored to its previous state on reboot.