Guides

MD5 vs SHA-256: Hashing Explained

Hashes are everywhere in computing — verifying downloads, storing passwords, signing data — and they're widely misunderstood. This guide explains what a hash is, how MD5 and SHA-256 differ, and which to use when (with one rule that prevents most security mistakes).

You can generate MD5, SHA-256 and HMAC hashes from text in your browser with the Hash Generator.

What is a hash?

A hash function takes any input — a word, a file, a gigabyte of data — and produces a fixed-length "fingerprint" called a digest. Good hash functions have three key properties:

  • Deterministic: the same input always produces the same hash.
  • Fixed size: "hi" and a 4 GB movie both produce a digest of the same length.
  • One-way: you can't reverse the hash to recover the input.
  • Avalanche effect: changing one character changes the entire hash unpredictably.

That one-way property is the crucial one — which brings us to the biggest myth.

⚠️ You don't "decrypt" a hash

Hashing is not encryption. There is no key and no reverse function. When someone "cracks" a hash, they're not decrypting it — they're guessing inputs, hashing each guess, and checking for a match (a brute-force or dictionary attack). That's why weak passwords fall quickly and strong, unique ones don't.

  • Encryption is reversible with a key (for secrecy).
  • Encoding like Base64 is reversible with no key (for transport).
  • Hashing is not reversible at all (for fingerprinting and integrity).

MD5 — fast, but cryptographically broken

MD5 produces a 128-bit (32-hex-character) digest. It's fast and was once everywhere, but it's broken for security: researchers can create collisions — two different inputs with the same MD5 hash — on demand. That means MD5 must never be used for passwords, digital signatures, or anything where an attacker benefits from forging a match.

Where MD5 is still fine: non-security checksums — a quick "did this file change?" or "did this download corrupt?" where nobody is trying to trick you. It's a fast integrity check, not a security guarantee.

SHA-256 — the modern default

SHA-256 (part of the SHA-2 family) produces a 256-bit (64-hex-character) digest and has no known practical collision attacks. It's the sensible default for:

  • Verifying file/download integrity where authenticity matters
  • Digital signatures and certificates
  • Blockchain and content addressing
  • Anywhere you'd have reached for MD5 "for security"

It's slightly slower than MD5 — irrelevant for almost every use, and a price well worth paying.

Quick comparison

MD5 SHA-256
Digest size 128-bit (32 hex) 256-bit (64 hex)
Collisions Practical, known None known
Security use ❌ Avoid ✅ Recommended
Non-security checksums ✅ OK ✅ Also fine
Speed Faster Slightly slower

Special case: passwords

For storing passwords, plain SHA-256 is still not enough. Fast hashes can be brute-forced at billions per second on a GPU. Password storage needs a slow, salted algorithm designed for the job — bcrypt, scrypt, or Argon2 — plus a unique random salt per user. Use your framework's built-in password hashing (for example, Laravel's Hash::make() uses bcrypt) rather than hashing passwords yourself.

What about HMAC?

HMAC (Hash-based Message Authentication Code) combines a hash with a secret key to verify both integrity and authenticity — proving a message wasn't tampered with and came from someone who knows the key. It's used to sign API requests and webhooks. The Hash Generator can produce HMAC-SHA256 if you need to check a signature.

Try it

With the Hash Generator you can:

  • Hash text with MD5, SHA-256, or HMAC-SHA256
  • See the avalanche effect — change one letter and watch the whole digest change
  • Do it locally; your input never leaves your browser

Frequently asked questions

Can I decrypt an MD5 or SHA-256 hash? No — hashing is one-way. "Reverse" lookups work only by guessing inputs and comparing hashes, which is why weak inputs are vulnerable and strong ones aren't.

Is MD5 safe to use? Not for security — collisions are practical. It's acceptable only as a fast, non-security checksum.

Should I use SHA-256 for passwords? No — even SHA-256 is too fast for password storage. Use bcrypt, scrypt or Argon2 with a per-user salt (your framework likely does this already).

Why do two files have the same hash sometimes? With a strong hash like SHA-256, that effectively never happens by chance. With MD5, collisions can be deliberately engineered — another reason to avoid it for security.

Pick the right tool: SHA-256 when authenticity matters, MD5 only for casual checksums, and a dedicated password hasher for passwords. Experiment with the Hash Generator to see how they behave.

Related Articles