MD5 Hash Generator
Generate MD5 hashes for text strings and data verification. MD5 produces a 128-bit (32 character hexadecimal) hash value. While no longer recommended for security purposes, MD5 remains widely used for checksums and data integrity verification.
Understanding MD5 Hashing
| Property | Value |
|---|---|
| Output length | 128 bits (16 bytes) |
| Hex representation | 32 characters |
| Speed | Very fast |
| Collision resistance | Broken (not secure) |
| Use case | Checksums, non-security |
MD5 Implementation
``javascript
// Using Web Crypto API (browser)
async function md5Hash(text) {
const encoder = new TextEncoder();
const data = encoder.encode(text);
// Note: Web Crypto doesn't support MD5
// Use a library like crypto-js
}
// Node.js
const crypto = require('crypto');
function md5(text) {
return crypto.createHash('md5').update(text).digest('hex');
}
// Example
md5('hello world');
// "5eb63bbbe01eeed093cb22bb8f5acdc3"
`
Common MD5 Use Cases
| Use Case | Example |
|---|---|
| File checksums | Verify downloads |
| Cache keys | md5(url + params) |
| Data deduplication | Compare file hashes |
| Legacy systems | Older password storage |
| ETags | HTTP caching |
Security Warning
MD5 has known vulnerabilities:
Collision attacks: Two different inputs can produce the same hash- Pre-image attacks: Possible to find input matching a hash
- Rainbow tables: Pre-computed hashes exist for common passwords
Never use MD5 for:
- Password hashing (use bcrypt, argon2)
- Digital signatures
- Certificate verification
- Any security-critical application
Verifying File Integrity
`bash
# Linux/Mac
md5sum filename.zip
# Windows
certutil -hashfile filename.zip MD5
`
Use MD5 for checksums and non-security applications only.
The Avalanche Effect
A one-character change produces a completely different digest — not a similar one. That
property is what makes a hash useful as a fingerprint:
| Input | MD5 | CRC32 |
|---|---|---|
hello | 5d41402abc4b2a76b9719d911017c592 | 3610a686 |
hello. | d94c10e437d18531e122ed0b45badd2a | 0a39d4f1 |
Hello | 8b1a9953c4611296a827abf8c47804d7 | f7d18982 |
hello and Hello differ by one bit of one byte, and share no part of their output.
RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is
d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.Digest Length and Collision Resistance
| Algorithm | Output | Birthday bound | Status |
|---|---|---|---|
| CRC32 | 32 bits | ~77,000 values | Checksum only |
| MD5 | 128 bits | 2⁶⁴ in theory | Broken — collisions in seconds |
| SHA-1 | 160 bits | 2⁸⁰ in theory | Broken — SHAttered, 2017 |
| RIPEMD-160 | 160 bits | 2⁸⁰ | No practical attack |
| SHA-256 | 256 bits | 2¹²⁸ | Current standard |
| SHA-512 | 512 bits | 2²⁵⁶ | Standard, faster on 64-bit |
Never Hash a Password With These
A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.