Only problem of software implementations is that they are reliant on the strength of the user-supplied passphrase, so there's a inverse correlation between user experience (ease of typing the passphrase) and security (easy passphrases are also easy to bruteforce).
A TPM provides hardware-backed bruteforce protection which means even an easy passphrase can be made secure as the number of attempts is rate-limited by the TPM (to a level much slower than even the hardest hashes).