I came across this Twitter thread and thought of your issue. Possibly this could be a solution?
https://twitter.com/mikeroySoft/status/1448675626714501122?ref_src=twsrc%5Etfw
VMX flag:
managedvm.autoAddVTPM="software"
Supposedly it only encrypts enough for the “secure enclave”, so perf should be way better, & no pwd.
|