StringMash.com

MD5 vs SHA-1 vs SHA-256

Three hash functions, two of them broken, and what each is still good for.

The short answer

Use SHA-256. MD5 (128-bit) and SHA-1 (160-bit) are both broken for security: practical collisions, two different inputs with the same hash, were published for MD5 in 2004 and for SHA-1 in 2017. They're still fine as quick checksums against accidental corruption, and both survive in older systems, but anything that relies on collision resistance, such as signatures and certificates, needs SHA-256 or newer.

All three on your own text

The lengths never change, whatever you type: 32, 40 and 64 hex digits.

MD5Broken
900150983cd24fb0d6963f7d28e17f7232 characters, 32 bytes
SHA-1Broken
a9993e364706816aba3e25717850c26c9cd0d89d40 characters, 40 bytes
SHA-256Current
ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad64 characters, 64 bytes
Open the hash generator →

Side by side

MD5SHA-1SHA-256
Output128 bits, 32 hex digits160 bits, 40 hex digits256 bits, 64 hex digits
StatusBroken: collisions since 2004Broken: public collision in 2017Secure
Still used forNon-security checksums, legacy systemsGit object names (hardened), legacy systemsSignatures, certificates, blockchains, general hashing
Use it for passwords?NoNoNo: use Argon2id, bcrypt or scrypt

What broke MD5 and SHA-1

A collision means two different inputs with the same hash, and for a function meant to fingerprint data, that's fatal: someone could get one document signed and swap in another. In August 2004 Xiaoyun Wang and colleagues announced collisions for full MD5, and the attacks only got cheaper. On 23 February 2017 the SHAttered project published two different PDF files with the same SHA-1 hash.

Git is the best-known SHA-1 user. Since version 2.13 it has used a hardened SHA-1 that isn't vulnerable to the SHAttered attack, and it can create repositories that use SHA-256 instead, though SHA-1 is still the default.

What about passwords?

None of the three. They're all designed to be fast, and fast is what an attacker guessing passwords wants. Password storage needs a slow, salted function. Hashing vs encryption explains why.

Questions

Is MD5 still safe to use?

Not for security. For spotting accidental corruption in a download it still works, but SHA-256 does that job too.

Is SHA-1 broken?

For collision resistance, yes, since the SHAttered collision in 2017.

Is SHA-256 secure?

Yes. No practical attack on SHA-256 is known.

What are the hashes of abc?

MD5 900150983cd24fb0d6963f7d28e17f72, SHA-1 a9993e364706816aba3e25717850c26c9cd0d89d, SHA-256 ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad.

Sources

Added . What's new