TECH SUPPORT GONE WRONG
Skills:
Security Basics80%
Key Takeaways
The video discusses a person's experience with Microsoft tech support, where they attempted to transfer a Windows 10 license to a new computer, but were unsuccessful due to a TPM requirement for Windows 11, and the support staff used an unofficial method to activate Windows 11, raising concerns about cybersecurity and support staff incentives.
Full Transcript
all right tiberias I saw this string of tweets from you if I can still call them that on Twitter and X all these posts about some Shenanigans a debacle that you ran into uh trying to activate Windows could you fill me in like what what all went down yeah so I guess let me start at the beginning which was technically 2020 so I a threeyear long story five five year John we're in 2025 right now my goodness oh time is a keep going so I I built my I built a computer in 2020 and I bought a Windows 10 license uh and I bought it from the Microsoft store so it was it was assigned to my Microsoft account installed Windows 10 perfectly fine and then obviously Windows 10 sort of support you know is ending this year and they were like flashing up I keep getting alerts saying oh your computer it doesn't support Windows 11 because it doesn't have a TPM those like well it's 5 years old I could probably build another PC it it's you know overdue for another PC I'll just get one with a TPM I'll you know get a nice Beast again right cuz it's slowing down already anyway so I built the other PC U the week before and I'd read that you could upgrade Windows 10 to Windows 11 for free if you'd already have a license and not only that they would let you switch Hardware like I Googled it there were several sites there were even like Microsoft answer sites which said yeah if if you switch the hardware it's a little bit of a process but you basically should just be able to do like a an activation and transfer the license from your other PC because it's technically associated with your Microsoft account and so I was like okay that's cool so I tried that and it didn't work like you select an option which is I've changed my hardware and then it should display a list of computers and it didn't like NE neither of them were there even though if you went to the website to microsoft.com and go to your account page and click devices both the computers were there so it's aware of them I've connected them to my account and it knows I have a license and even if I I went to like the orders page and I scrolled back 5 years and it says Windows 10/11 so I was like well the license is there it's in my account this should be a simple support issue there was I and I went through all the proper channels so there's on the activation page there's a get help like button that you click and you enter in your phone number and it says we'll give you a call back so this was all within Windows 11 like I didn't I wasn't scammed I didn't just get a random call from tech support and the this was the first call because this was a whole Saga but the first call the uh the first person I spoke to we tried various things for 20 minutes honestly it was basically everything I'd already tried they were just talking me through it they said they were going to transfer me and they were going to tell the person they were transferring me to all the details I I don't know why this is just an aside but it doesn't look like Microsoft's transfer thing works because as soon as I was transferred after about a 20 minute wait on hold they were like what's the problem and I'm like don't you know and they're like nope and I was like I was you the person the previous person said they were transferring me and they were like this isn't a transfer it just comes through as a new call and like well that's great explain the whole issue again they can't help so they're like we'll transfer you so I'm now been on the phone for about an hour though most of it on hold um and then finally about 20 minutes later after that like I was transferred to another person who literally just mentioned well maybe we have to reinstall Windows 10 I'm like what and then they just put me on they put me on hold for no reason so I was like you know screw this I'm going to hang up and I issue another call back because I'm just I just had enough I there's so many things I could have been doing but yeah so I hang up I go through the whole get help process again and this time I have to wait like 4 hours for the call back but eventually it comes through and the first person again is really no help they actually gave me a reference number which is the first time you know they happened yeah right so that was great and then they transferred me and half an hour later after I was on hold for half an hour I transferred to a guy and they were like what seems to be the problem and I'm like I have a reference number now which they used like oh it seems Seems like you're having activation issues and like yeah and we go through it and it it's just I don't know I don't know why it's taking me to the fifth person but he's the first person who's like well let me remote onto your computer and I don't know you can do something like control Windows key Q to get like a a buil-in quick assist yeah so we do that and he's like let's let me try and reinstall Windows 11 so he downloads the iso opens it up on on the desktop goes through the whole setup thing again reinstalls Windows 11 so that takes like 20 minutes restarts the computer we do the quick assist thing again go to activate it no nothing and i' I've been tweeting by the way this entire time like just frustration like been an hour and a half or now everything's happening and I'd actually never heard of this um this script before what's it called again you never heard of mass grave I've never heard of mass grave before because honestly I I've only activated Windows like 10 once right and it was 5 years ago yeah yeah I've never actually heard of masc grave and people have been suggesting it and I was like well I want to do this legitimately I already paid $200 like 5 years ago I I don't really feel like I should be running these scripts like you know whatever I don't care if people do but so I only heard about it that day and then literally like 10 minutes before this this event went down um one person tweeted it again and I was just like laughing it's like no I won't and then I see the guy so he's he's just failed to activate Windows 11 and he just pulls up poell and just literally he puts in the command that you you get it's the first command on the masquerave site yeah just puts it in and I'm just looking going like what like and I see like I see the menu pop up and he selects whatever option I kind remember what it was but he selects the option it does something goes away he goes to the windows settings page and behold Windows is activated and he's like there it's activated now and I'm like thanks like I could have done that guy and then it's like yeah and then I was like you'll never guess what just happened wow yeah that's it but like it's just crazy because yeah I mean like I I tweeted out another thing which is it is a security issue right like it's yeah it's a trusted script because so many people use it but it's a third party script it's hosted on third party Services it's just weird that Microsoft tech support using it I mean but it got to jump on I guess yeah I don't know I've never particularly made a video on mass grave or talked about it too much on my side just cuz I have normally been in the similar situation or the mindset as you is like okay if I need to activate Windows then I'll just do it for real with purchasing it whatever but like in all the videos that I've seen people kind of give me Flack for oh to activate Windows icon is in the bottom right all the time cuz I just leave it unactivated like that's fine but it'd be good to do it and folks suggest massg grave but massg grave is as you mentioned like not official Microsoft though now I guess official Microsoft is using it clearly so I want to go take a look at that bleeping computer article I'd love to read a little bit more but like the script as you run your irm invoke rest method and uh URL pipe toex invoke expression looks like a sketchy download cradle in power sh that you just see all the time for malware but this one is not but it does pull down a lot of other GitHub hosted scripts where sure maybe someway somehow there's the opportunity for supply chain Shenanigans but it's just funny yeah I think that's the takeway it's just the it's just funny that they apparently I mean this is the thing I feel like even though I was talking with official Microsoft tech support I imagine they contract that out to other companies like there's a question whether you know these are actual Microsoft employees or not so I don't know that's a good point but I imagine I I did read the bleeping computer article I believe Microsoft made a comment which was that this was not official procedure and they were going to have words with whoever did it can I track it down with with your reference number now right oh wow well goodness gracious I guess that's the Spiel that's the story is there any more to sprinkle in or you think that's that's just kind of the gist it's I yeah I mean there it's just an interesting one because it's technically an exploit right that's the thing and there's the other angle which is this is hosted on GitHub and Microsoft own GitHub and but this this is the thing I I commented earlier on Twitter as well like I feel like they they could definitely remove it from GitHub I think it would be a PR nightmare just because there are so many Microsoft and just Windows exploits on GitHub anyway like if if that's the reason you know like where does it stop if they start removing stuff true so that's that's a slippery slope play I Feel Like is why they haven't removed it now can they patch the actual exploit I don't know to you're saying exploit is in like the method to activate Windows not through the usual Puttin Windows activation key yeah yeah right yeah I think I mean I don't know there probably a debate I think it classes an exploit it's definitely bypassing an activation feature of some kind like exploit security vulnerability I don't know it's it's doing something that Windows really doesn't want you to do but Microsoft said here you go Microsoft support I think actually that is you do bring up so is there anything deep to this story it's possible this is more indicative of whatever sort of incentives there support people have for fixing tickets quickly like that's that's the thing I've spoken to people who've worked in support before and there's sometimes like just big incentives to have to close a lot of tickets and it looks bad if you have tickets open for ages and it might just be this like I was on the phone with this last guy for like about half an hour because we were installing Windows 11 so that was like 20 minutes at least it might just be that he was trying to close the case and thought well I can get away with it this time or you know whatever but I don't know it's definitely not not what you really really want to do to solve an actual Windows activation issue but then Windows activation is just broken I guess in general yeah that's just a a wild funny story I am very very interested on folks opinions on their thoughts on what they'll chime in with in the comments cuz I think a lot of folks will be like oh masef and just as you mention hey folks suggesting that even in the first problem predicament in the first place but now huh how does it all look when it's kind of used from The Source you didn't expect but anyway goodness gracious thank you so much for hopping on the horn to tell me the story I don't I I it is funny to tell the story at least make some folks aware yeah no no problem John thank you for thank you so much for having me
Original Description
Tib3rius' Channel: @Tib3rius https://www.youtube.com/tib3rius
0xTib3rius Twitter/X: https://x.com/0xTib3rius
Thread: https://x.com/0xTib3rius/status/1896333858943193358
Learn Cybersecurity and more with Just Hacking Training: https://jh.live/training
See what else I'm up to with: https://jh.live/newsletter
ℹ️ Affiliates:
Learn how to code with CodeCrafters: https://jh.live/codecrafters
Host your own VPN with OpenVPN: https://jh.live/openvpn
Get DFIR and SOC Analyst Training with CyberDefenders: https://jh.live/cyberdefense
Master Binary Files and Protocols with Gynvael Coldwind: https://jh.live/hackarcana (code MBF-JH-10 gives 10% off!)
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: Security Basics
View skill →Related AI Lessons
🎓
Tutor Explanation
DeepCamp AI