In theory, you shouldn't be able to get the key while booting on some other media (say, your own Windows USB drive).
> Ensuring the integrity of early boot components and boot configuration data. On devices that have a TPM version 1.2 or higher, BitLocker uses the enhanced security capabilities of the TPM to make data accessible only if the computer’s BIOS firmware code and configuration, original boot sequence, boot components, and BCD configuration all appear unaltered and the encrypted disk is located in the original computer. On systems that leverage TPM PCR[7], BCD setting changes deemed safe are permitted to improve usability.
https://docs.microsoft.com/en-us/windows/security/informatio...
Consoles are largely protected by the same technology, how often do you see people achieving code execution on them by tampering with the hardware?
Also, consoles are "protecting" not the user, but the manufacturer - which is exactly the point people are trying to make.
What hardmods do you know of for current gen consoles? Even the previous generation mostly fixed all public hardware based attacks.
This is standardized hardware that would be a relatively soft target to build tooling against, yet modchips are essentially dead because the attacks are just far too difficult.
That there are still no good attacks for the xbox one speaks volumes.