MD5 vs SHA-256: What's the Difference
MD5 and SHA-256 are both hash functions — they turn any input into a fixed-length fingerprint — but MD5's 128-bit digest is cryptographically broken, while SHA-256 produces a 256-bit digest and remains secure. Use SHA-256 for passwords, signatures, and integrity checks; MD5 is only fine for non-security uses like checksums. Compare both on our free hash generator.
- The short answer
- What a hash function actually does
- MD5: the 128-bit workhorse
- SHA-256: the 256-bit standard
- Head to head: MD5 vs SHA-256
- How MD5 broke — and what 'broken' really means
- Which should you use? A decision guide
- See it yourself: the word 'hello', hashed
- Verifying a download with a checksum, step by step
- Generate MD5, SHA-256, and more in one click
The short answer
A hash function takes any input — a password, a file, a novel — and produces a fixed-length 'fingerprint' called a digest. MD5 always outputs 128 bits (written as 32 hex characters); SHA-256 always outputs 256 bits (64 hex characters). Both are deterministic: the same input always gives the same digest, and changing one letter of the input scrambles the output completely. The difference that matters is security: researchers can now craft two different inputs with the same MD5 digest — a collision — which breaks MD5 for anything adversarial, like certificates or file verification against attackers. SHA-256 has no practical collision attack and is the current standard. So: SHA-256 for security, MD5 only where no attacker is involved.
What a hash function actually does
Three properties define a cryptographic hash. Determinism: hash the same file a thousand times, get the same digest a thousand times — this is what makes checksums useful. The avalanche effect: flip one bit of input and roughly half the output bits change, so similar inputs have wildly different digests — there is no 'close' in hash space. One-wayness: given only the digest, reconstructing the input should be infeasible — you can verify a password by hashing the guess and comparing digests without ever storing the password itself. A fourth property, collision resistance, says nobody should be able to find two different inputs with the same digest. MD5 fails this fourth property today, which is precisely what 'broken' means — the first three still hold. Understanding which property your use case needs is the key to choosing correctly.
MD5: the 128-bit workhorse
MD5 was designed by Ronald Rivest in 1991 as a fast message digest for integrity checking, and for over a decade it was everywhere: file checksums, password storage (regrettably), data deduplication. Its 128-bit output fits in 32 hex characters — short enough to eyeball-compare and cheap to store. It is also fast: on modern hardware MD5 chews through gigabytes per second, noticeably quicker than SHA-256. That speed-plus-compactness combination is why it refuses to die. It survives legitimately in non-adversarial roles: checksumming downloads against accidental corruption, fingerprinting files for deduplication, generating deterministic ids from content. The rule is simple: if the worst case is random corruption rather than a motivated attacker, MD5 remains a perfectly good tool. The moment an attacker enters the picture, retire it.
SHA-256: the 256-bit standard
SHA-256 is one of the SHA-2 family, published by NIST in 2001, and it is the workhorse of modern security infrastructure. Its 64-hex-character digest gives 2²⁵⁶ possible outputs — a number so large that brute force is physically meaningless; you would need more energy than the sun will ever produce to have a real chance. SHA-256 secures TLS certificates, signs software updates, anchors the Bitcoin blockchain (miners race to find inputs whose SHA-256 digest starts with enough zeros), and sits inside password-hashing schemes and HMAC constructions — including the signatures on JWT tokens. It is slower than MD5 by design-adjacent accident (more rounds, bigger state), but on modern CPUs the difference is irrelevant for anything short of bulk data processing. When in doubt, SHA-256 is the default answer.
Head to head: MD5 vs SHA-256
Digest size: 128 bits vs 256 bits — SHA-256's space is 2¹²⁸ times larger, which is the entire security story in one number. Output length: 32 vs 64 hex characters. Speed: MD5 is roughly twice as fast in software, though both exceed a gigabyte per second on modern hardware. Collision resistance: MD5 is broken — practical collision attacks exist and run in seconds on a laptop; SHA-256 has no practical attack, with the best known results still purely theoretical. Preimage resistance (reversing a digest): both still hold, though MD5's margin is thinner. Adoption: MD5 lingers in legacy systems and checksums; SHA-256 is mandated or default in TLS, code signing, Git's transition plans, and cryptocurrencies. Bottom line: they are not competitors anymore — MD5 is a legacy utility, SHA-256 is the standard. The comparison matters only because so much MD5-era infrastructure still needs migrating.
How MD5 broke — and what 'broken' really means
The fall took a decade. In 2004 researchers demonstrated practical MD5 collisions — two different inputs, same digest — and by 2008 the attack was weaponized: researchers forged a rogue certificate authority certificate by colliding certificate requests, undermining the web's trust model. In 2012 the Flame malware used an MD5 collision to fake Microsoft code-signing. 'Broken' here has a precise meaning: collision resistance is dead. But nuance matters — preimage attacks (finding an input for a given digest, i.e., reversing a hash) remain infeasible at around 2¹²³ operations, so MD5 still hides passwords from casual reversal. The practical upshot: MD5 is unsafe wherever an attacker can choose the inputs — signatures, certificates, file verification against tampering. It is fine where inputs are not attacker-controlled — accidental-corruption checksums, hash tables, content fingerprints. 'Broken' does not mean 'useless'; it means 'know exactly which property you are relying on.'
Which should you use? A decision guide
Verifying downloads or files against tampering: SHA-256, always — checksums from a vendor assume an attacker might swap the file. Checksumming against accidental corruption (did my copy complete?): MD5 is fine and faster, though SHA-256 costs little. Storing passwords: neither raw — use Argon2, bcrypt, or scrypt, which are deliberately slow to blunt brute force; raw SHA-256 of a password falls to GPUs in hours, and MD5 in minutes. Signing data or tokens: SHA-256 inside HMAC or RSA/ECDSA — this is what JWT signatures use. Deduplicating files or generating content ids: MD5 is acceptable, SHA-256 if you want margin. Checksums in legacy protocols that mandate MD5: use it, but understand the protocol is the weak link. And if you are building something new and unsure: SHA-256. It is never the wrong choice; MD5 sometimes is.
See it yourself: the word 'hello', hashed
Here are real digests, computed for this article — paste 'hello' into any hash tool to confirm. MD5('hello') = 5d41402abc4b2a76b9719d911017c592 (32 characters). SHA-256('hello') = 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 (64 characters). Now change one letter — 'Hello' with a capital H — and both digests change beyond recognition: that is the avalanche effect, and you can watch it live in our free hash generator. Notice the lengths: you can identify the algorithm from digest length alone, a handy trick when staring at an unknown hash in a config file or database. Also notice neither digest reveals anything about the input — 'hello' is nowhere visible in either string, which is the one-way property at work.
Verifying a download with a checksum, step by step
This is the most common real-world use of hashing, and it takes thirty seconds. Step 1: the software vendor publishes a SHA-256 checksum alongside the download — a 64-character string on their download page. Step 2: download the file. Step 3: hash the file locally — on our hash generator you can drop the file itself in, no upload involved, or use shasum -a 256 filename on Mac/Linux. Step 4: compare the two strings character by character. Match: the file is exactly what the vendor published — no corruption, no tampering. Mismatch: delete it and re-download; never install a mismatched binary. This single habit defeats corrupted downloads, man-in-the-middle swaps, and compromised mirrors. Vendors publish MD5 checksums too on older pages — they still catch accidental corruption, but for security-sensitive software, insist on SHA-256.
Generate MD5, SHA-256, and more in one click
Our free hash generator computes MD5, SHA-1, SHA-256, and SHA-512 from typed text or a dropped file — instantly, in your browser, with nothing uploaded. It is the fastest way to compare algorithms side by side, verify a checksum, or fingerprint a file. Hashing passwords? Read how to create a strong password first — then hash it properly. Curious where hashes guard web logins? That is how JWT tokens work, signatures included. And for the data formats hashes usually protect, see what JSON is.