What's the plan, encrypt the data a public key where the private key is locked most of the time? Require a passphrase any time you want to read or process it? Does anyone think that UX will fly? Maybe there's some TPM magic that makes it work without also making it trivial to steal for an attacker who already has arbitrary code execution, but no one is citing that so far. I don't see the better design that everyone seems to think is obviously there. (Besides the obvious Just Don't, which is fair as far as it goes but has nothing to do with crypto)