Well, potentially a key might be stored in TPM. But I don't think that's better

I would hope that it is harder to get into the TPM than into the RAM.