Algorithms
MD5
A 128-bit hash broken for collisions since 2004. Still on download pages and in checksum files and it has HMAC
Hash / Legacy
MD5
Broken since 2004, still on every download page.
- Digest
- 128-bit · 16 bytes
- HMAC
- takes a key
- Security
- BROKEN: collision attacks known since 2004
- Family
- 2 in legacy
2 options, 0 required
Sample
- hex
- 5eb63bbbe01eeed093cb22bb8f5acdc3
- base64
- XrY7u+Ae7tCTyyK7j1rNww==
Options
Access
- Create
create("md5") - CLI
hashes md5 'hello world' - Tryplayground with the sample above
- Kinsha1
Broken. Collisions have been cheap since 2004 and chosen-prefix collisions since 2007, which is how Flame forged a Microsoft signature. Don't sign anything with it, don't dedup anything an attacker gets to choose.
And yet it's on every mirror's checksum file, in old databases and in ETags. So it's here, in the legacy family, for matching what somebody else computed.
create("md5").hash("").digest; // "d41d8cd98f00b204e9800998ecf8427e"
create("md5").hash("hello").digest; // "5d41402abc4b2a76b9719d911017c592"
HMAC-MD5 isn't broken the way MD5 is, since HMAC doesn't need collision resistance. It's still a bad choice for anything new.