100% this. And if you expect people to discover the software they need on their own then you need a superb software discovery experience. AFAIK Ubuntu does not have that at the moment. I read they are working on a better software center but wonder if that will be enough.
Is it still possible to add an extra key (in another slot) to unlock it with cryptsetup? Adding this extra key might beat the purpose of using the TPM but if you choose a long random key and store it in a password manager that should still be pretty safe right?