TPM-Sniffing LUKS Keys on an Embedded Linux Device [CVE-2026-0714]
cyloq.se
cyloq.se
Notably both of these turn it into a 'microscope' problem, alternatively if the key leaks somewhere…
At the end of the day, if the system is to process the data, it needs to access it. (Homomorphic encryption nonwithstanding.)
The only "truly" 'safe-ish' thing is active battery powered intrusion detection. It's done for high end HSMs… which easily sell for 5 or 6 digit prices.