

I don’t think chain of trust and security through kernel-level access are fighting the same problem.
Usually chain of trust is to prevent app tampering, and kernel-level access is to prevent memory tampering.
I assume Windows is creating a new API for applications to monitor certain regions of memory for tampering without needing kernel access.
“it says here you clicked ‘sign me up for ISIS’ 10000 times?”
“Haha no officer, you see it was my social chaff AI that clicked it”