This approach doesn't give access from the hypervisor to your private keys it gives access to other tenants to your private keys.