What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For a new security-sensitive use that needs collision resistance, choose SHA-256, not MD5. MD5 may still serve as an inline checksum for detecting accidental errors, but it does not establish who supplied a file. For password storage, use neither as a bare hash: choose a suitable salted password-hashing scheme with an appropriately high cost factor.

MD5 and SHA-256 at a glance

Both algorithms turn an input message into a fixed-length digest. The digest can help detect changes to that message, but the algorithms differ in output length and, more importantly, in whether they are appropriate when an attacker may try to exploit collisions.

Question MD5 SHA-256
Digest length 128 bits, specified by the IETF in RFC 6151 (2011). 256 bits, specified by NIST in FIPS 180-4 (2015).
Expected collision resistance The IETF says MD5 is not prudent when collision resistance is required. 128 bits, as described by NIST SP 800-107 Rev. 1 (2012).
Expected preimage resistance No comparable estimate is given in the cited material. 256 bits, as described by NIST SP 800-107 Rev. 1 (2012).
Suitable for password storage as a single fast hash? No. No.

Digest length alone does not tell the whole security story. A collision attack seeks two different inputs with the same digest; a preimage attack seeks an input matching a chosen digest. NIST also distinguishes second-preimage resistance: finding a different input that matches the digest of a particular input. These are different attack goals, so their strength figures should not be treated as interchangeable.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When should you use SHA-256?

Use SHA-256 for a new cryptographic design that requires collision resistance, including digital-signature-related uses. RFC 6151 says MD5 is no longer acceptable where collision resistance is required, such as digital signatures. SHA-256 is part of NIST’s Secure Hash Standard, which describes secure hashes as useful for detecting message changes and in digital-signature verification and message-authentication codes.

SHA-256’s 256-bit digest has an expected collision resistance of 128 bits and an expected preimage resistance of 256 bits, according to NIST SP 800-107 Rev. 1 (2012). These are security-strength estimates, not performance measurements or guarantees that every use of SHA-256 is secure. The surrounding design still matters.

When is MD5 acceptable?

The IETF’s RFC 6151 allows a narrow legacy case: an MD5 checksum used inline solely to protect against errors. In that situation, it may detect accidental corruption, provided the application clearly states the security service it expects. This exception does not make MD5 suitable where an attacker can deliberately construct inputs or where collision resistance is required.

Do not treat an unauthenticated checksum as proof of origin. If an attacker can replace both a downloaded file and the checksum published beside it, comparing the two will not reveal the substitution. For download verification when malicious replacement is in scope, obtain the digest through a trustworthy authenticated channel or verify a digital signature.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why neither hash is a password-storage recommendation

A single MD5 or SHA-256 digest is not an appropriate password-storage scheme. General-purpose hashes are designed to calculate quickly; if password hashes are stolen, that makes repeated guessing more practical. NIST SP 800-63B Revision 4 says verifiers should store passwords in a form resistant to offline attacks, using a suitable password-hashing scheme with a salt and cost factor. The cost factor should be as high as practical without harming verifier performance. Choosing SHA-256 merely because it is stronger than MD5 does not address this separate problem.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does SHA-256 run faster than MD5?

No general speed ranking is established here. Performance depends on the implementation, platform, and workload, and the cited standards are not comparable current benchmarks. Do not choose MD5 for a security-sensitive task on the assumption that it will be faster in your environment; benchmark the actual implementation if performance is a deciding factor, while keeping the security requirement fixed.

Standards and source dates

  • RFC 6151, published by the IETF in March 2011, describes MD5’s limitations and its narrow error-checking exception.
  • NIST FIPS 180-4, published in August 2015, specifies SHA-256 as part of the Secure Hash Standard and describes hash use for detecting message changes. NIST recorded a March 2023 planning note that it had decided to revise the standard after public comment; consult NIST for a successor when making a compliance decision.
  • NIST SP 800-107 Rev. 1 (2012) explains hash security-strength estimates, including SHA-256’s expected collision and preimage resistance.
  • NIST SP 800-63B Revision 4 provides password-storage guidance on salts, suitable password-hashing schemes, and cost factors.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.