Your parent comment said he was assuming a PIN was used to seal the TPM, and the attacking the link would have failed if the TPM had a PIN set, no? I agree though that using a TPM without a PIN gives little in the way of data protection. Not nothing, but little.
Sniffing the bus can be defeated by using encrypted comms. It is disabled by Windows for some reason, but it works as designed in other secure boot implementations. I hope :)