MD5 vs SHA-1 vs SHA-256: Which Hash Should You Use?

A clear comparison of MD5, SHA-1, SHA-256 and SHA-512: digest sizes, known attacks, speed, and the right use cases for checksums, signatures and HMAC.

Last updated · 2026-08-30

What a hash guarantees

A cryptographic hash should be one-way (you cannot recover the input), deterministic, and collision-resistant (finding two inputs with the same output should be infeasible). When collision resistance breaks, the algorithm is no longer safe for signatures or certificates.

MD5

MD5 produces a 128-bit digest. Practical collisions have been known since 2004 and were used to forge a certificate authority in 2008. Today MD5 is acceptable only for non-adversarial uses: detecting accidental file corruption, cache keys or deduplication.

SHA-1

SHA-1 produces 160 bits. Google's SHAttered attack produced the first real collision in 2017, and chosen-prefix collisions became affordable in 2020. Browsers no longer accept SHA-1 certificates and Git is migrating to SHA-256.

SHA-256 and SHA-512

Part of the SHA-2 family, they produce 256 and 512 bits respectively and have no practical attacks. SHA-256 is the default for TLS certificates, code signing, Bitcoin and file checksums. SHA-512 is often faster on 64-bit CPUs. SHA-3 exists as a structurally different backup.

HMAC for authenticity

A plain hash proves integrity only if the hash itself is trusted. To prove a message came from someone holding a secret — for example webhook signatures from Stripe or GitHub — use HMAC-SHA256 and compare signatures with a constant-time function.

import crypto from "node:crypto";
const sig = crypto.createHmac("sha256", secret).update(body).digest("hex");
crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(received));

Never for passwords

None of these algorithms should store passwords, even SHA-512 with a salt. They are too fast. Use bcrypt or Argon2id, explained in our Bcrypt vs Argon2 article.

Try the tools from this article

← All tutorials