Stuff like this always reminds me of that guy (haven't seen him in decades, sadly). Oh, you used AES encryption? That's lovely, but your computer knows the key and I can trick it into telling me it.
Truecrypt likely changed the game on some of the claims he made, but that conversations predated it's existence.
Today the angle of attack seems to be around OTP + Password with a timeout on the credentials generated. It narrows the window, but doesn't completely block it.