Of interest is discussion of credentials (which might make Wave's ACM - Attestation Credential Manager - a useful property to be working on.
Also of interest, the Nexus is split into two parts. One part (the inner Nexus), appears to run in hardware below Ring 0. In the Q&A section there are hints that Microsoft may not be the owner of the code that runs in the inner Nexus.