Docuboxer
By Sergio Alonzo Piña··5 min read

Is MD5 still safe? MD5 vs SHA-256 explained

A plain answer on which hash fits which job, with the cases where MD5 is still fine and the one job no plain hash should do.

MD5 is not safe wherever someone might want to forge data: practical collisions are known. SHA-256 is the default pick for integrity checks, and neither is a way to store passwords. With the hash generator you can compute MD5, SHA-1, SHA-256, SHA-384 and SHA-512 for text or a file in your browser and compare the result to a published checksum, with the file never leaving your device.

MD5, SHA-1 and SHA-256 side by side

AlgorithmHash lengthStatus
MD532 hex charactersPractical collisions known, not for security
SHA-140 charactersA real collision shown in 2017, retired from security use
SHA-25664 charactersCurrent, part of the SHA-2 family
SHA-38496 charactersCurrent, SHA-2
SHA-512128 charactersCurrent, SHA-2

A collision means two different inputs produce the same hash. For MD5 they have been constructible for years, and RFC 6151 summarizes its security problems. For SHA-1, researchers at CWI Amsterdam and Google produced the first real collision in 2017, two different PDFs sharing one SHA-1. There is no comparable known attack on SHA-256.

Reading a hash

Each hexadecimal character carries 4 bits, so the lengths in the table correspond to 128, 160, 256, 384 and 512 bits. Upper and lower case mean the same thing, which is why a checksum comparison should ignore case. The number after SHA is the output size in bits. SHA-2 is the family name, and the tool offers its 256, 384 and 512 bit variants.

So when is MD5 still fine?

When nobody is trying to fool you: spotting a file that got corrupted in a copy, building a cache key, or matching a legacy checksum that only exists as MD5. If an adversary is plausible, such as software downloads, signed artifacts or anything security-related, use SHA-256 or stronger.

Check a download against its published checksum

  1. Find the checksum on the download page, often labeled SHA-256.
  2. Open the hash generator, switch to file input and drop the downloaded file.
  3. Paste the published value into Compare with expected hash. Case and spaces are ignored, a prefix such as SHA-256: is accepted, so is the output of sha256sum with the file name, and the algorithm is detected from the length (32, 40, 64, 96 or 128 characters).
  4. Read the message. A match means the computed hash is identical to the expected one. A mismatch means the file isn't the original, or the pasted hash belongs to another file.

If what you paste isn't a hash, the tool says a hash can only contain digits 0 to 9 and letters a to f, and when the length fits no algorithm it lists how long each full hash should be. There's also a link to search the hash on VirusTotal, a hash-only lookup that doesn't upload your file.

A limit that matters

A checksum published on the same page as the file confirms the download arrived intact, but it can't tell you the site wasn't tampered with, since whoever swaps the file can swap the hash too. For that you need a signature or a checksum obtained through a separate trusted channel.

Why not hash passwords with SHA-256?

Plain hashes are fast on purpose, which lets an attacker test enormous numbers of guesses per second. The OWASP password storage cheat sheet states that fast algorithms such as SHA-256 are unsuitable for passwords and recommends deliberately slow ones, with Argon2id first. If your own password turned up somewhere, see your password was in a data breach, now what?

Hashes in everyday tools

Checksums show up in more places than software downloads: package registries list them, backup tools use them to detect changed files, and some systems use them to deduplicate uploads. In each case the same logic holds. A match says the bytes are the same, a mismatch says they differ, and neither says anything about whether the content is safe.

A hash is not encryption

There is no key and nothing to decrypt. Same input, same output, and the original can't be recovered from the output, although weak inputs can be guessed by trying candidates until one hashes to the same value. If you're confusing the idea with encoding, what is Base64 draws the line.

Frequently asked questions

What is the difference between MD5 and SHA-256?

MD5 produces a 32-character hash and has known practical collisions, so it isn't considered secure. SHA-256 produces 64 characters and remains current. For integrity checks where security matters, use SHA-256.

Is MD5 still safe to use?

Not for security. It's fine for detecting accidental corruption or matching legacy checksums, but it gives no guarantee if someone can tamper with the data on purpose.

How do I verify the checksum of a downloaded file?

Compute its hash with the same algorithm the site publishes and compare it with the published value. If they're identical, the file didn't change. If not, the download is incomplete or isn't the original file.

Can I use SHA-256 to store passwords?

No. It's too fast, so it allows huge numbers of guesses per second. Passwords call for slow algorithms such as Argon2id, scrypt or PBKDF2, with a salt.

Can a hash be reversed?

There is no way to recover the original from its hash. What attackers do is try known inputs until one produces the same hash, which is why weak passwords fall even when hashed.

Is my file uploaded when I compute the hash?

No. The calculation runs in your browser. You can check the Network tab in developer tools: analytics requests show up, but no POST or PUT the size of your file.

Hash a file or compare a checksum

MD5, SHA-1, SHA-256, SHA-384 and SHA-512 for text or files, with an expected-hash check. Free, no signup.

Open Hash Generator →

Related tools

  • Hash Generator: MD5, SHA-1, SHA-256, SHA-384 and SHA-512, with expected-hash comparison.
  • Password Check: see whether a password appeared in known breaches.
  • File Inspector: check what a file really is, beyond its extension.
  • Base64: encode and decode, another transformation that isn't encryption.

You might also like: what is Base64? Encoding explained in plain English, 13 developer tools that respect your privacy, Strong password: why length beats complexity and What's inside a JWT? Decoding vs verifying.