Even keeping keys in special hardware such as a TPM isn’t enough if all it’s doing is limiting the number of times you can guess the hard disk encryption password, but then copying the master key to main memory once you get the password right so that the CPU can do the rest of the work (Ross Anderson, "#SecurityEngineering — Third Edition", PDF-Preview 2020-05-16)