https://en.wikipedia.org/wiki/Trusted_Platform_Module#Field_...
For ASIC-only devices, the keys are burned-in, which is user-hostile too.