Glossary

MD5

MD5 (Message-Digest Algorithm 5) is a cryptographic hash function that produces a 128-bit (16-byte) digest, conventionally shown as 32 hexadecimal characters. Designed by Ronald Rivest in 1991 and specified in RFC 1321, it was once the most widely used hash on the web before being thoroughly broken as a security tool.

How it works

MD5 processes input in 512-bit blocks and always produces the same 16-byte digest regardless of input length, in principle behaving like any other one-way hash function: deterministic output, and (originally) computational infeasibility of finding two inputs that hash to the same value.

Example:

MD5("abc") = 900150983cd24fb0d6963f7d28e17f72

That collision resistance is exactly what failed. In 2004, Wang, Feng, Lai, and Yu published a practical method for generating MD5 collisions, and by 2007–2008 researchers demonstrated chosen-prefix collisions — crafting two files with attacker-chosen, meaningfully different content that still hash identically. This was later used to forge a rogue certificate authority certificate (2008) and, notoriously, by the Flame malware (2012) to forge a Microsoft code-signing certificate. MD5 has not been considered safe for any security-relevant use since.

Common pitfalls

  • Never use MD5 for passwords, digital signatures, certificate fingerprints, or anything where an attacker benefits from crafting a collision.
  • MD5 is still commonly seen for non-adversarial integrity checks (verifying a download wasn't corrupted in transit) — a legitimate but narrow use case that has nothing to do with security.
  • A matching MD5 checksum was historically treated as strong proof of file integrity; that assumption is no longer safe once an adversary can influence either file.
  • Don't confuse "broken" with "reversible" — MD5 collisions let an attacker find two different inputs with the same hash, not recover the original input from a digest.

Related terms

  • SHA-1 — a stronger, but also now-broken, hash function of the same era.
  • SHA-256 — the modern hash function with no known practical collision, used wherever MD5 or SHA-1 would have been used a decade ago.
  • HMAC — wrapping MD5 in an HMAC construction (HMAC-MD5) mitigates the specific collision attacks that break plain MD5, though HMAC-SHA256 is the safer modern default.

See also

  • Tool: Hash Generator — compute MD5 digests (alongside SHA-1, SHA-256, and SHA-512) from text for legacy checksum compatibility.