This article, however, says that this setup does not protect the data at all against a thief willing to pay $100 lifetime (not per machine), which seems an absurdly low bar. (And I’d wager you can go even lower by wiring up a cheap devboard—basically everything has a SPI peripheral these days.) I mean, liquid nitrogen is not exactly expensive either, but it does require some fuss, whereas the attack in TFA could be made essentially as easy as opening the case.
But I still can’t get over the idea where the default configuration of BitLocker is completely useless for basically anything except working around storage devices that will lie to you and not erase things you told them to. I just refuse to accept that’s in any way sane.