Earlier quoted context omitted.
Cloud servers ============= Xen supports virtual TPM. I'm no Amazon EC2 expert, but a quick google exposed a few keen souls who tried to use vTPM and failed. This would suggest that Amazon does not yet support vTPM. Re-entering passphrases ======================== Well, unless the machine is permissioned by default you will need to give a fresh instance new authorization. Permissioning by default is the same security…
sniffing isn't the main issue I'm trying to avoid, it's accidental exposure. I.e. minimising the risk that during normal operations the secrets get exposed somehow.
I would say that you should consider malicious sniffing too