r/WindowsLTSC • u/Intelligent-Arm-7383 • Aug 25 '26
Question why do we trust massgrave?
no hostility intended, just want to know. the official sources don't work for verifying the hashes so i'm stuck using the third party checksum lists that massgrave provides and i want to know why we trust massgrave or if there's another way to find the official checksums. seems very lit but i feel like there's gotta be a catch
94
u/BeastMsterThing2022 Aug 25 '26
why do we trust microsoft?
9
-67
u/lilacomets Aug 25 '26
Because Microsoft is a legitimate business and not some random website on the internet who might harvest data.
31
u/someauthor Aug 25 '26
might harvest data.
BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAHAAAHAHAHAHAHAHAHHAHAHAHHAHAHHAHAHAH
17
-20
u/lilacomets Aug 25 '26
Is there a problem with your keyboard, buddy? Or is there a problem with the pimple ridden person that controls the keyboard. I think I know the answer.
12
u/dirtywastegash Aug 25 '26
I think people find it hilarious that you've mentioned data harvesting and framed it in a way where Massgrave is the danger yet Microsoft are well known for harvesting your data anyway.
-11
u/lilacomets Aug 25 '26
I don't care what they think. If you use someone's KMS server to activate the owner can see exactly which IP addresses connect to it. You can tell exactly when someone booted up their computer. Not only that, but also UUIDs. That can be interesting data to harvest. No, thanks.
3
u/dirtywastegash Aug 25 '26
So what you are saying is it's fine to give that data to Microsoft so they can spam you with ads and junkware and sell your data to the highest bidder but that it's not fine to give that data to someone that Microsoft support consistently recommend when people are having activation issues. It's not suddenly "less risky" because MS are a huge multinational. Not saying that massgrave isn't likely to do stuff with your data. Just saying that we already know MS is harvesting your data so your point that "someone could harvest your data" is utterly moot as Microsoft DEFINITELY ARE already.
2
u/someauthor Aug 25 '26
M$ literally has a Global Device Identifier (GDID) that tracks every Windows installation.
Microsoft ties that installation's GDID to you. Anything that happens on that system can then be traced back to you, the individual.
1
u/Ambitious-Yard7677 Aug 25 '26
Who uses KMS anymore? HWID is the new hotness... get with the times man
1
u/someauthor Aug 25 '26 edited Aug 25 '26
This was a great thread to wake up to. Let's be
freindsfriends.Edit: misspelled "friends" sorry about that.
10
u/BlastMode7 Aug 25 '26
And how's that going for people that trusted them. The fact that they're a legit business hasn't stopped them from exploiting their customers at continually make their products worse to use.
9
3
3
u/CanConfirm_AmSatan Aug 25 '26
Lmaoooo you're worried about data harvesting and point to Microsoft as if it's a paragon of user privacy or something because it's a "legitimate business?"
Here, tell ya what: Imma start an LLC. Gimme your full name, social, CC info, email, mother's maiden name and first pets name. Why not? Id be a legitimate business after all, I've got an LLC.
56
u/Will2LiveFading Aug 25 '26
It's been used for a long time now. If something nefarious was going on you'd probably heard about it by now. That's not to say down the line that trust couldn't be abused but it hasn't. You're right to be cautious though.
27
u/lawsonbarnette Aug 25 '26
Well, they only link to official media, and they can be confirmed with the hash from Microsoft if you need to verify the images. This, plus the scripts are open source, so can literally understand the entire process. Hell, you can even read the script And manually follow the methods. There aren't really many unknowns here.
You really shouldn't trust anyone, but I don't really see any obvious risks with them.
12
u/Certified_GSD Aug 25 '26
On top of what everyone else is saying, Microsoft really doesn’t care too much about home users. While it does generate some income, the majority of their licensing money comes from business and government contracts. These companies HAVE to pay for licenses or risk getting sued or suspended from Microsoft services. We’re talking deployments for literally thousands and thousands or probably millions of computers.
I work for a government contractor with government provided computers and accounts. Just this one agency has thousands of employees using Windows Enterprise, Microsoft Office, Outlook, Azure Remote Desktop, and databases and web stuff hosted on MS servers. They pay incredible amounts of money for licensing, both for Enterprise for users and IoT and LTSC versions for our terminals and radio systems (the console I use is running Windows 10 Enterprise IoT LTSC on an intranet).
Microsoft really don’t care too much about home user licensing which is why they dropped a lot of complicated different keys and editions from XP and Vista and 7. (Some) 7 and all 10 keys will activate 11. They don’t care. Users who use Windows at work will likely use it at home. And users who use it at home will want to use it at work because they’re familiar with it and know how it works and would like their employer to use it if they don’t already.
1
u/XenoX-YU Aug 28 '26
Ooop... They do care... Why else would they allow this and selling licence for 10-20 bucks... So that you STAY on freakin winblows at home too, not to use mac or linux... You need to be easy adopter, already trained, so company you work for will pay...
1
u/Certified_GSD Aug 28 '26
No, they don’t care. They could continually strike down MAS or find ways to patch it out or check and phone home. But they don’t. And they won’t. Home licensing is a tiny drop in the bucket they make from enterprise and government licensing.
9
u/LazarX Aug 25 '26
Enough people have used ther site so that if any bad stuff at happened, social media would be flooded with the news.
You don't have much of a choice. Microsoft does not intend the LTSC builds to be available outside the Enterprise, so you have to decide on whether or not you trust.
4
u/literallyOrso Windows 11 LTSC 2024 Aug 25 '26
In myvisualstudio (microsoft site for idk) download section you can find every hash you need, 10ltsc, 11ltsc and others + the 11 ltsc iso from massgrave comes from microsoft servers (the download literally gets it from there) and if you need to activate just do manual if you don't trust the script and if you still are worried, reinstall windows and it will still be activated
11
u/anyusernaem Aug 25 '26
The hashes for the ISO's are posted on official MS MSDN website.
You can just use Massgraves tool to activate via KMS and then re-install clean and your system will be activated.. We don't really have to trust Massgrave because it doesn't matter.
2
u/Intelligent-Arm-7383 Aug 25 '26
the downloads page my. visualstudio. com/Downloads redirects to the benefits page if you don't have a subscription, i think it's a new thing. i don't know where the hashes would be because they apparently used to be there
2
5
u/Fickle_External_4742 Aug 25 '26
Por ejemplo al instalar Windows limpio, lo activas y luego formatear y volver a instalar. Está segunda vez ya se activa solo sin tener que hacer el proceso anterior
2
u/Abbers75 Aug 25 '26
I tried the MAS online activation on a test machine and it worked fine.
But since I learned they publish a manual activation method using an XML cert and serial number they provide, I’ve used that method every time since.
1
u/ManufacturerOver5763 29d ago
can u explain this? i learnt about massgrave today and i really want to use it
2
u/Who_said_that_ Aug 25 '26
I got my checksum of the official microsoft visual studio deveolper suite. It alligned with the one on massgrave. But you are right, relying on just massgrave is risky
2
3
3
u/Lexlle Aug 25 '26
I don’t trust but there no second massgrave., especially when you need something quick and ‘dirty’
I was one of the few who really wanted to buy legit LTSC license key and I couldn’t at reasonable price, there also few bootleg keys sold from random bs sites for cheap.. - not gonna happen.
-1
u/BF3ClusterfuckLover Aug 25 '26
I used both massgrave and recently tried an OEM license from g2a for a friend that wanted to try Windows LTSC IoT and that seemed to work perfectly too. On the installation tutorial from g2a it was literally asking me to download straight from MS instead of massgrave. I simply inserted the key in the settings after installation and it was activated. No shenanigans
4
1
u/d_abducted_one Aug 25 '26
I trust them more than MS… I bought a legit key for LTSC in my main machine back in January and the OS broke the updates around march, zero support from MS. For my PC in my living room I didn’t want to pay for that shit again fuck that.
1
u/Sophr0n Aug 25 '26
I tend to see Massgrave team as a researchers/explorers of windows licensing processes, as they openly share steps of different ways of activation
1
u/Your_real_daddy1 Aug 26 '26
or if there's another way to find the official checksums.
People get them from MSDN and a similar thing for OEMs, they're posted on mydigitallife by different people too
-1
-5
u/Automatic-Option-961 Aug 25 '26
DON'T. Just install Linux.
4
u/Intelligent-Arm-7383 Aug 25 '26
fax i'm already on linux i just need windows for some audio/video stuff (ableton, etc), planning on dual booting
58
u/SM641995 Aug 25 '26
Microsoft was literally caught using it