> a default ubuntu install could mount and decrypt a bitlocker encrypted windows drive with no trouble
This means BitLocker was off or "Pending Activation," so the Volume Master Key (VMK) was available in plaintext rather than sealed.
When BitLocker is "On," the default is to seal the VMK using TPM PCRs 0, 2, 4, 7, and 11, so tampering with the Firmware (PCR0), UEFI Extensions (PCR2), UEFI Boot (PCR4), Secure Boot State (PCR7), or the BitLocker state itself (PCR11) will result in a failure to decrypt the key. Of course, there are vulnerabilities at every stage (especially sniffing key material as it transits the TPM), but the concept is reasonably sound.