Well, it turns out you can actually get hardware devices which store private keys on their hardware and don’t let you export them. What if it was stored in a physical piece of hardware? Or maybe you are still using log4J and someone can write a malicious text entry which would log all the credentials
