http://hn.vernccvbvyi5qhfzyqengccj7lkove6bjot2xhh5kajhwvidqafczrad.onion/stories/33847869
Yes, one can generate keys
on a TPM that can be extracted or sent to
specific other TPMs, or not at all, at
the user's choice. Which means that one
can set up a ring of TPMs to hold a given
key, for example. I.e., TPMs can
function as HSMs. cryptonector 3y I've written a tutorial on TPMs.