I was disappointed when I installed linux on my laptop to find that a default ubuntu install could mount and decrypt a bitlocker encrypted windows drive with no trouble - while I was under the impression that the encryption keys were locked deep in the TPM and couldn't be extracted by anything but a securely booted windows installation.
https://superuser.com/questions/1299600/is-a-volume-with-bit...
Er, what? Of course you do! At least if you've chosen to encrypt it. That's the whole point of doing so! Using Bitlocker is the explicit opt-in.
Then an errant bios update can brick the computer.
(Please don't) ask me how I know.
This means it's an opt-out situation and the user probably isn't aware that a boot failure or hardware failure can brick all his data that he really should keep backups of.
Popular linux distros being behind Windows on this front is one of the key reasons I still daily Windows.
This means BitLocker was off or "Pending Activation," so the Volume Master Key (VMK) was available in plaintext rather than sealed.
When BitLocker is "On," the default is to seal the VMK using TPM PCRs 0, 2, 4, 7, and 11, so tampering with the Firmware (PCR0), UEFI Extensions (PCR2), UEFI Boot (PCR4), Secure Boot State (PCR7), or the BitLocker state itself (PCR11) will result in a failure to decrypt the key. Of course, there are vulnerabilities at every stage (especially sniffing key material as it transits the TPM), but the concept is reasonably sound.