My thoughts on how to configure your systems to protect against the Dolos Group's excellent demonstration of sniffing TPM protected disk encryption keys: https://trmm.net/tpm-sniffing/
@th heh locking the door and putting the key under the door mat... also bitlocker with TPM actively prevents you from restoring your files when your mobo breaks.