Skip to content

Developers · 7 min read

MD5 vs SHA256 vs SHA-1: which hash should you use?

MD5 and SHA-1 have both been broken by real collision attacks. SHA-256 hasn't. Here's what that means in practice, which one to use for what, and how to check a download's checksum on any computer.

In short

  • Use SHA-256 for anything new. MD5 (2004) and SHA-1 (2017) both have practical collision attacks.
  • MD5 and SHA-1 still catch accidental corruption, so an old MD5 checksum is fine for spotting a damaged download, but not for proving a file wasn't tampered with.
  • None of the three should store passwords. Use Argon2id, scrypt or bcrypt, which are slow on purpose.
  • Check a file on Windows with certutil -hashfile file SHA256, on a Mac with shasum -a 256 file, and on Linux with sha256sum file.

MD5 vs SHA256: the short answer

Use SHA-256 (often written SHA256). It produces a longer fingerprint, has no known practical attacks, and on modern processors it's often faster than MD5. Use MD5 or SHA-1 only when a system you can't change requires them, or when you just need to detect accidental corruption and nobody has a reason to fake a match.

For passwords, the answer is none of them. Fast hashes let an attacker test billions of guesses; password storage needs a deliberately slow algorithm, covered below.

What is a hash?

A hash function turns input of any size into a fixed-length fingerprint called a digest. The same input always gives the same digest, and changing a single character gives a completely different one:

Input   MD5                               SHA-256
hello   5d41402abc4b2a76b9719d911017c592  2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
Hello   8b1a9953c4611296a827abf8c47804d7  185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969

A cryptographic hash also needs to be one-way (you can't work back from the digest to the input) and collision resistant (nobody can find two different inputs with the same digest). Collisions must exist, since infinitely many inputs map to a fixed number of outputs, but for a secure hash finding one should take an impractical amount of computing. When researchers find a shortcut, the hash is considered broken for security uses.

Hashing isn't encryption. There's no key and no way to decrypt a digest; if you need to get the original back later, encrypt it instead, for example with our AES text encryption tool. Sites that claim to decrypt MD5 hashes are looking the digest up in huge tables of precomputed hashes of common words and passwords. It also isn't encoding: Base64 can be reversed by anyone with a Base64 decoder, as our Base64 explainer shows, while a hash can't be reversed at all.

MD5 vs SHA-1 vs SHA-256 compared

We measured speed with OpenSSL 3.0 on one core of a 2.1 GHz Intel Xeon cloud server, hashing 16 KB blocks. This CPU has the SHA extensions found in many recent Intel and AMD processors, which speed up SHA-1 and SHA-256 but not MD5.

MD5SHA-1SHA-256
Published1992 (RFC 1321)1995 (FIPS 180-1)2002 (FIPS 180-2)
Digest length128 bits, 32 hex characters160 bits, 40 hex characters256 bits, 64 hex characters
Speed in our testAbout 580 MB/sAbout 1,430 MB/sAbout 1,350 MB/s
First practical collision20042017None known
StatusBroken; RFC 6151 rules it out wherever collision resistance mattersDeprecated; NIST says phase out by 31 December 2030Recommended
Still fine forDetecting accidental corruption, cache keys, legacy systemsSame as MD5, plus HMAC-SHA1 in older protocolsChecksums, signatures, certificates, HMAC

The speed result surprises people who learned that MD5 is the fast one. On older processors without SHA instructions MD5 usually does win, but the gap doesn't justify using it. You can tell the algorithms apart by length alone: 32, 40 or 64 hex characters.

Is MD5 secure?

Not for anything an attacker might target. In August 2004, Xiaoyun Wang, Dengguo Feng, Xuejia Lai and Hongbo Yu published collisions for MD5 and several related hashes (Cryptology ePrint 2004/199). Attacks then got cheaper and more flexible. The most damaging is the chosen-prefix collision, where an attacker starts from two different meaningful files and appends data until their digests match.

That attack was used in the wild. The Flame espionage malware, found in 2012, carried a forged Microsoft code-signing certificate. Cryptanalyst Marc Stevens at CWI showed it was made with a previously unknown variant of an MD5 chosen-prefix collision attack against a Microsoft certificate authority that still accepted MD5 signatures. RFC 6151 (2011) had already stated that MD5 is no longer acceptable where collision resistance is required, such as digital signatures.

What MD5 still does well is catch accidents. A flipped bit from a bad download or a failing disk changes the digest, and random damage won't produce a collision. If a project only publishes an MD5 checksum, checking it is better than not checking, but it can't prove the file came from the publisher.

SHA-1 vs SHA-256: SHAttered and after

SHA-1 lasted longer. On 23 February 2017, researchers from CWI Amsterdam and Google announced SHAttered: two different PDF files with the same SHA-1 digest. It took about nine quintillion SHA-1 computations, roughly 6,500 CPU-years and 110 GPU-years, which Google said was about 100,000 times faster than a brute-force attack.

In 2020, Gaëtan Leurent and Thomas Peyrin published "SHA-1 is a Shambles", the first chosen-prefix collision for SHA-1, and estimated its cost at about US$45,000 of rented GPU time (US$11,000 for a plain collision). They used it to show forged PGP key certifications. In December 2022 NIST announced that SHA-1 should be phased out by 31 December 2030 in favour of SHA-2 and SHA-3.

SHA-256 belongs to the SHA-2 family, alongside SHA-224, SHA-384 and SHA-512. No practical collision or preimage attack on it is known. One caveat for developers: SHA-256 on its own allows length-extension attacks, so to authenticate a message with a secret key, use HMAC-SHA256 instead of hashing the secret and message together.

Hashes and passwords: use Argon2, scrypt or bcrypt

Speed is good for checksums and bad for passwords. In our test one CPU core computed about 5 million SHA-256 hashes per second of short inputs; an attacker with stolen hashes and GPUs can try far more. The OWASP Password Storage Cheat Sheet states that fast algorithms such as SHA-256 are not suitable for password storage, and recommends, in order:

  • Argon2id with at least 19 MiB of memory, 2 iterations and 1 degree of parallelism.
  • scrypt with a CPU/memory cost of at least 2^17, block size 8 and parallelism 1, if Argon2id isn't available.
  • bcrypt for legacy systems, with a work factor of 10 or more. Most implementations only read the first 72 bytes of a password.
  • PBKDF2-HMAC-SHA256 with 600,000 iterations when FIPS-140 compliance is required.

All of these add a unique random salt per password, so identical passwords produce different hashes and precomputed tables don't work. Use your framework's built-in password hashing rather than writing your own. For generating the passwords themselves, our password generator runs in the browser.

How to verify a file checksum on Windows, Mac and Linux

Download the file and its published checksum from the official site, compute the hash locally, and compare. Hex digests aren't case-sensitive, so 2CF24D... and 2cf24d... are the same value. If they differ by even one character, download again.

Windows

Both tools are built in. certutil works in Command Prompt; in PowerShell, Get-FileHash uses SHA256 unless you pass -Algorithm:

REM Command Prompt
certutil -hashfile C:\Users\you\Downloads\installer.iso SHA256

# PowerShell (SHA256 is the default)
Get-FileHash .\installer.iso
Get-FileHash .\installer.iso -Algorithm MD5

# PowerShell: compare with the published value (-eq ignores case)
(Get-FileHash .\installer.iso).Hash -eq "2CF24DBA5FB0A30E26E83B2AC5B9E29E1B161E5C1FA7425E73043362938B9824"

Mac

macOS includes shasum for the SHA family and md5 for MD5:

shasum -a 256 ~/Downloads/installer.dmg
shasum -a 1 ~/Downloads/installer.dmg
md5 ~/Downloads/installer.dmg

# Check against a published value (two spaces before the file name)
echo "2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824  installer.dmg" | shasum -a 256 -c

Linux

GNU coreutils has one command per algorithm. The -c option reads a checksum file, such as the SHA256SUMS many Linux distributions publish, and prints OK or FAILED for each file:

sha256sum installer.iso
md5sum installer.iso
sha1sum installer.iso

# Check every file listed in a checksum file you downloaded
sha256sum -c SHA256SUMS --ignore-missing

In the browser

Our hash generator computes MD5, SHA-1 and SHA-256 of text or any file at once, and its compare box tells you whether a pasted checksum matches. The file is read locally and isn't uploaded.

Frequently asked questions

Is MD5 still safe to use?

Not for security. Practical MD5 collisions have existed since 2004 and were used to forge a Microsoft certificate in the Flame malware. It's still acceptable for spotting accidental file corruption or as a non-security cache key.

Can a hash be decrypted?

No. A hash has no key and throws information away, so there's nothing to decrypt. Online "MD5 decrypters" only look up digests of common words and passwords they computed in advance.

Is SHA-256 secure?

Yes. No practical collision or preimage attack on SHA-256 is known, and NIST recommends the SHA-2 family, which includes SHA-256, as a replacement for SHA-1. It still shouldn't be used alone for passwords, because it's too fast.

What is the difference between SHA-1 and SHA-256?

SHA-1 produces a 160-bit digest (40 hex characters) and has had practical collisions since 2017. SHA-256 produces a 256-bit digest (64 hex characters) and has none known. Use SHA-256.

Which hash should I use for passwords?

None of MD5, SHA-1 or SHA-256. OWASP recommends Argon2id first, then scrypt, with bcrypt for legacy systems and PBKDF2 with 600,000 iterations where FIPS compliance is required.

How do I check a SHA256 checksum on Windows?

Open Command Prompt and run certutil -hashfile path\to\file SHA256, or in PowerShell run Get-FileHash path\to\file. Compare the result with the checksum published on the download page.

Sources

Published 11 October 2026Written and fact-checked by the ToolzyLab teamEditorial policy