>The use of a discrete (physical) TPM actually decreases the security of the system, using a fTPM would solve the problem. Errr... no. Using no TPM of any kind decreases your security. The discrete TPM's threat model was never designed to cover you from attackers using oscilloscope to probe your laptop's SPI bus during the boot process for unencrypted data. Unencrypted communications over any channel, SW or HW are ba…
This is highly misleading. fTPM is more secure against _this_ kind of attack, with physical access to the bus wires. However, since fTPM is a Firmware-TPM, it is vulnerable to all kinds of attacks on the system's firmware, even remotely, even via the network, even maybe if the computer is switched off. Remember all those (even unauthenticated, remote) XML-parser exploits in the Intel ME? fTPM is just one more ME modu…
Once you are online Bitlocker does nothing and you can just attack the OS and bypass all of its protections trivially...
Your threat model here assumes arbitrary code execution as a starting point of an exploit, the security game is up for the PC once that occurs.