TPM definitely rises the effort by a lot to break it. But by default the communication with it is not encrypted, so especially for modules not built into the cpu wire/bus-tapping is a thing.
https://news.ycombinator.com/item?id=46676919
Just use fTPM?
Just use fTPM?