MD5 vs SHA-256: Hashing Explained
Hashes are everywhere in computing — verifying downloads, storing passwords, signing data — and they're widely misunderstood. This guide explains what a hash is, how MD5 and SHA-256 differ, and which to use when (with one rule that prevents most security mistakes).
You can generate MD5, SHA-256 and HMAC hashes from text in your browser with the Hash Generator.
What is a hash?
A hash function takes any input — a word, a file, a gigabyte of data — and produces a fixed-length "fingerprint" called a digest. Good hash functions have three key properties:
- Deterministic: the same input always produces the same hash.
- Fixed size: "hi" and a 4 GB movie both produce a digest of the same length.
- One-way: you can't reverse the hash to recover the input.
- Avalanche effect: changing one character changes the entire hash unpredictably.
That one-way property is the crucial one — which brings us to the biggest myth.
⚠️ You don't "decrypt" a hash
Hashing is not encryption. There is no key and no reverse function. When someone "cracks" a hash, they're not decrypting it — they're guessing inputs, hashing each guess, and checking for a match (a brute-force or dictionary attack). That's why weak passwords fall quickly and strong, unique ones don't.
- Encryption is reversible with a key (for secrecy).
- Encoding like Base64 is reversible with no key (for transport).
- Hashing is not reversible at all (for fingerprinting and integrity).
MD5 — fast, but cryptographically broken
MD5 produces a 128-bit (32-hex-character) digest. It's fast and was once everywhere, but it's broken for security: researchers can create collisions — two different inputs with the same MD5 hash — on demand. That means MD5 must never be used for passwords, digital signatures, or anything where an attacker benefits from forging a match.
Where MD5 is still fine: non-security checksums — a quick "did this file change?" or "did this download corrupt?" where nobody is trying to trick you. It's a fast integrity check, not a security guarantee.
SHA-256 — the modern default
SHA-256 (part of the SHA-2 family) produces a 256-bit (64-hex-character) digest and has no known practical collision attacks. It's the sensible default for:
- Verifying file/download integrity where authenticity matters
- Digital signatures and certificates
- Blockchain and content addressing
- Anywhere you'd have reached for MD5 "for security"
It's slightly slower than MD5 — irrelevant for almost every use, and a price well worth paying.
Quick comparison
| MD5 | SHA-256 | |
|---|---|---|
| Digest size | 128-bit (32 hex) | 256-bit (64 hex) |
| Collisions | Practical, known | None known |
| Security use | ❌ Avoid | ✅ Recommended |
| Non-security checksums | ✅ OK | ✅ Also fine |
| Speed | Faster | Slightly slower |
Special case: passwords
For storing passwords, plain SHA-256 is still not enough. Fast hashes can be brute-forced at billions per second on a GPU. Password storage needs a slow, salted algorithm designed for the job — bcrypt, scrypt, or Argon2 — plus a unique random salt per user. Use your framework's built-in password hashing (for example, Laravel's Hash::make() uses bcrypt) rather than hashing passwords yourself.
What about HMAC?
HMAC (Hash-based Message Authentication Code) combines a hash with a secret key to verify both integrity and authenticity — proving a message wasn't tampered with and came from someone who knows the key. It's used to sign API requests and webhooks. The Hash Generator can produce HMAC-SHA256 if you need to check a signature.
Try it
With the Hash Generator you can:
- Hash text with MD5, SHA-256, or HMAC-SHA256
- See the avalanche effect — change one letter and watch the whole digest change
- Do it locally; your input never leaves your browser
Frequently asked questions
Can I decrypt an MD5 or SHA-256 hash? No — hashing is one-way. "Reverse" lookups work only by guessing inputs and comparing hashes, which is why weak inputs are vulnerable and strong ones aren't.
Is MD5 safe to use? Not for security — collisions are practical. It's acceptable only as a fast, non-security checksum.
Should I use SHA-256 for passwords? No — even SHA-256 is too fast for password storage. Use bcrypt, scrypt or Argon2 with a per-user salt (your framework likely does this already).
Why do two files have the same hash sometimes? With a strong hash like SHA-256, that effectively never happens by chance. With MD5, collisions can be deliberately engineered — another reason to avoid it for security.
Pick the right tool: SHA-256 when authenticity matters, MD5 only for casual checksums, and a dedicated password hasher for passwords. Experiment with the Hash Generator to see how they behave.
Tags:
Related Articles
How to Convert Images to PDF (JPG & PNG to PDF)
Turn one or many JPG, PNG or WebP images into a single, tidy PDF — with the right page order, size and margins. Free and entirely in your browser.
How to Edit a PDF for Free in Your Browser
Reorder, rotate and delete pages, add text and highlights, sign documents and fill forms — all for free in your browser, with no upload and no watermark.
PNG vs JPEG vs WebP: Which Image Format Should You Use?
PNG, JPEG and WebP each win in different situations. Here's a clear, practical breakdown of when to use each — with real guidance on quality, transparency, and file size.