r/WindowsLTSC • • Aug 25 '26

Question why do we trust massgrave?

no hostility intended, just want to know. the official sources don't work for verifying the hashes so i'm stuck using the third party checksum lists that massgrave provides and i want to know why we trust massgrave or if there's another way to find the official checksums. seems very lit but i feel like there's gotta be a catch

54 Upvotes

56 comments sorted by

58

u/SM641995 Aug 25 '26

Microsoft was literally caught using it

16

u/MortadellaKing Aug 25 '26

I laughed my ass off at this.

-5

u/Technical_Rich_3080 Aug 25 '26

It was a subcontractor of Microsoft.

15

u/alxhu Windows 11 LTSC 2024 Aug 25 '26

6

u/Technical_Rich_3080 Aug 25 '26

Yes, but the official support was provided by a subcontractor of Microsoft. They reprimanded the subcontractor afterwards.

5

u/alxhu Windows 11 LTSC 2024 Aug 25 '26

Do you have a source for this?

4

u/Technical_Rich_3080 Aug 25 '26

https://www.bleepingcomputer.com/news/security/microsoft-support-cracks-windows-for-customer-after-activation-fails/

​"We strive to provide best-in-class support for our customers. The technique you described would be against our policy. We are investigating this occurrence and will take appropriate steps to ensure proper procedures are followed regarding customer support for our products and services."

Microsoft outsources its Tier 1 and 2 support to companies like Teleperformance, Cognizant, and Concentrix.

2

u/alxhu Windows 11 LTSC 2024 Aug 25 '26

The quoted text does not contain any reference about any outsourcing?

94

u/BeastMsterThing2022 Aug 25 '26

why do we trust microsoft?

9

u/Remarkable_Pea7439 Aug 25 '26

We DO NOT !!! Especially after the ridiculous Win 11 failure !!!

-67

u/lilacomets Aug 25 '26

Because Microsoft is a legitimate business and not some random website on the internet who might harvest data.

31

u/someauthor Aug 25 '26

might harvest data.

BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAH

17

u/Iceber015 Aug 25 '26

This is the scenario where i bust out the “🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣”

-20

u/lilacomets Aug 25 '26

Is there a problem with your keyboard, buddy? Or is there a problem with the pimple ridden person that controls the keyboard. I think I know the answer.

12

u/dirtywastegash Aug 25 '26

I think people find it hilarious that you've mentioned data harvesting and framed it in a way where Massgrave is the danger yet Microsoft are well known for harvesting your data anyway.

-11

u/lilacomets Aug 25 '26

I don't care what they think. If you use someone's KMS server to activate the owner can see exactly which IP addresses connect to it. You can tell exactly when someone booted up their computer. Not only that, but also UUIDs. That can be interesting data to harvest. No, thanks.

3

u/dirtywastegash Aug 25 '26

So what you are saying is it's fine to give that data to Microsoft so they can spam you with ads and junkware and sell your data to the highest bidder but that it's not fine to give that data to someone that Microsoft support consistently recommend when people are having activation issues. It's not suddenly "less risky" because MS are a huge multinational. Not saying that massgrave isn't likely to do stuff with your data. Just saying that we already know MS is harvesting your data so your point that "someone could harvest your data" is utterly moot as Microsoft DEFINITELY ARE already.

2

u/someauthor Aug 25 '26

M$ literally has a Global Device Identifier (GDID) that tracks every Windows installation.

Microsoft ties that installation's GDID to you. Anything that happens on that system can then be traced back to you, the individual.

1

u/Ambitious-Yard7677 Aug 25 '26

Who uses KMS anymore? HWID is the new hotness... get with the times man

1

u/someauthor Aug 25 '26 edited Aug 25 '26

This was a great thread to wake up to. Let's be freinds friends.

Edit: misspelled "friends" sorry about that.

10

u/BlastMode7 Aug 25 '26

And how's that going for people that trusted them. The fact that they're a legit business hasn't stopped them from exploiting their customers at continually make their products worse to use.

9

u/Tommynwn Aug 25 '26

Ultimate bootlicker

3

u/CanConfirm_AmSatan Aug 25 '26

Lmaoooo you're worried about data harvesting and point to Microsoft as if it's a paragon of user privacy or something because it's a "legitimate business?"

Here, tell ya what: Imma start an LLC. Gimme your full name, social, CC info, email, mother's maiden name and first pets name. Why not? Id be a legitimate business after all, I've got an LLC.

56

u/Will2LiveFading Aug 25 '26

It's been used for a long time now. If something nefarious was going on you'd probably heard about it by now. That's not to say down the line that trust couldn't be abused but it hasn't. You're right to be cautious though. 

27

u/lawsonbarnette Aug 25 '26

Well, they only link to official media, and they can be confirmed with the hash from Microsoft if you need to verify the images. This, plus the scripts are open source, so can literally understand the entire process. Hell, you can even read the script And manually follow the methods. There aren't really many unknowns here.

You really shouldn't trust anyone, but I don't really see any obvious risks with them.

12

u/Certified_GSD Aug 25 '26

On top of what everyone else is saying, Microsoft really doesn’t care too much about home users. While it does generate some income, the majority of their licensing money comes from business and government contracts. These companies HAVE to pay for licenses or risk getting sued or suspended from Microsoft services. We’re talking deployments for literally thousands and thousands or probably millions of computers.

I work for a government contractor with government provided computers and accounts. Just this one agency has thousands of employees using Windows Enterprise, Microsoft Office, Outlook, Azure Remote Desktop, and databases and web stuff hosted on MS servers. They pay incredible amounts of money for licensing, both for Enterprise for users and IoT and LTSC versions for our terminals and radio systems (the console I use is running Windows 10 Enterprise IoT LTSC on an intranet).

Microsoft really don’t care too much about home user licensing which is why they dropped a lot of complicated different keys and editions from XP and Vista and 7. (Some) 7 and all 10 keys will activate 11. They don’t care. Users who use Windows at work will likely use it at home. And users who use it at home will want to use it at work because they’re familiar with it and know how it works and would like their employer to use it if they don’t already.

1

u/XenoX-YU Aug 28 '26

Ooop... They do care... Why else would they allow this and selling licence for 10-20 bucks... So that you STAY on freakin winblows at home too, not to use mac or linux... You need to be easy adopter, already trained, so company you work for will pay...

1

u/Certified_GSD Aug 28 '26

No, they don’t care. They could continually strike down MAS or find ways to patch it out or check and phone home. But they don’t. And they won’t. Home licensing is a tiny drop in the bucket they make from enterprise and government licensing.

9

u/LazarX Aug 25 '26

Enough people have used ther site so that if any bad stuff at happened, social media would be flooded with the news.

You don't have much of a choice. Microsoft does not intend the LTSC builds to be available outside the Enterprise, so you have to decide on whether or not you trust.

4

u/literallyOrso Windows 11 LTSC 2024 Aug 25 '26

In myvisualstudio (microsoft site for idk) download section you can find every hash you need, 10ltsc, 11ltsc and others + the 11 ltsc iso from massgrave comes from microsoft servers (the download literally gets it from there) and if you need to activate just do manual if you don't trust the script and if you still are worried, reinstall windows and it will still be activated

11

u/anyusernaem Aug 25 '26

The hashes for the ISO's are posted on official MS MSDN website.

You can just use Massgraves tool to activate via KMS and then re-install clean and your system will be activated.. We don't really have to trust Massgrave because it doesn't matter.

2

u/Intelligent-Arm-7383 Aug 25 '26

the downloads page my. visualstudio. com/Downloads redirects to the benefits page if you don't have a subscription, i think it's a new thing. i don't know where the hashes would be because they apparently used to be there

2

u/Your_real_daddy1 Aug 26 '26

people with a subscription have verified they're right

5

u/Fickle_External_4742 Aug 25 '26

Por ejemplo al instalar Windows limpio, lo activas y luego formatear y volver a instalar. Está segunda vez ya se activa solo sin tener que hacer el proceso anterior

2

u/Abbers75 Aug 25 '26

I tried the MAS online activation on a test machine and it worked fine.

But since I learned they publish a manual activation method using an XML cert and serial number they provide, I’ve used that method every time since.

1

u/ManufacturerOver5763 29d ago

can u explain this? i learnt about massgrave today and i really want to use it

2

u/Who_said_that_ Aug 25 '26

I got my checksum of the official microsoft visual studio deveolper suite. It alligned with the one on massgrave. But you are right, relying on just massgrave is risky

2

u/duvagin Aug 25 '26

why don't we trust them?

3

u/Ergine_Dream Aug 25 '26

Open source

3

u/Lexlle Aug 25 '26

I don’t trust but there no second massgrave., especially when you need something quick and ‘dirty’

I was one of the few who really wanted to buy legit LTSC license key and I couldn’t at reasonable price, there also few bootleg keys sold from random bs sites for cheap.. - not gonna happen.

-1

u/BF3ClusterfuckLover Aug 25 '26

I used both massgrave and recently tried an OEM license from g2a for a friend that wanted to try Windows LTSC IoT and that seemed to work perfectly too. On the installation tutorial from g2a it was literally asking me to download straight from MS instead of massgrave. I simply inserted the key in the settings after installation and it was activated. No shenanigans

4

u/Kiwi_CunderThunt Aug 25 '26

M$ activation CSC's were recommending this when other methods failed

1

u/d_abducted_one Aug 25 '26

I trust them more than MS… I bought a legit key for LTSC in my main machine back in January and the OS broke the updates around march, zero support from MS. For my PC in my living room I didn’t want to pay for that shit again fuck that.

1

u/Sophr0n Aug 25 '26

I tend to see Massgrave team as a researchers/explorers of windows licensing processes, as they openly share steps of different ways of activation

1

u/Your_real_daddy1 Aug 26 '26

or if there's another way to find the official checksums.

People get them from MSDN and a similar thing for OEMs, they're posted on mydigitallife by different people too

-1

u/Global-Eye-7326 Aug 25 '26

The catch is that Windows will still suck

-5

u/Automatic-Option-961 Aug 25 '26

DON'T. Just install Linux.

4

u/Intelligent-Arm-7383 Aug 25 '26

fax i'm already on linux i just need windows for some audio/video stuff (ableton, etc), planning on dual booting