Speaking of TPM and its 'tamper-proof'ness, the enlightenment framework I developed disables all versons of IMA, a TPM-enabled kernel level Tripwire of sorts, in such a way that any remote monitoring host will not notice anything suspicious.
'Tamper-proof' is highly dependent upon implementation.