Alex Rivera | Logout

Is MD5 less secure than SHA et. al. in a practical sense?

Asked 2009-04-21T03:12:46.610
9

I've seen a few questions and answers on SO suggesting that MD5 is less secure than something like SHA.

My question is, Is this worth worrying about in my situation?

Here's an example of how I'm using it:

  1. On the client side, I'm providing a "secure" checksum for a message by appending the current time and a password and then hashing it using MD5. So: MD5(message+time+password).
  2. On the server side, I'm checking this hash against the message that's sent using my knowledge of the time it was sent and the client's password.

In this example, am I really better off using SHA instead of MD5?

In what circumstances would the choice of hashing function really matter in a practical sense?

Edit:

Just to clarify - in my example, is there any benefit moving to an SHA algorithm?

In other words, is it feasible in this example for someone to send a message and a correct hash without knowing the shared password?

More Edits:

Apologies for repeated editing - I wasn't being clear with what I was asking.

Edit
Report

2 Answers

8

Brian's answer covers the issues, but I do think it needs to be explained a little less verbosely

You are using the wrong crypto algorithm here

MD5 is wrong here, Sha1 is wrong to use here Sha2xx is wrong to use and Skein is wrong to use.

What you should be using is something like RSA.

Let me explain:

Your secure hash is effectively sending the password out for the world to see.

You mention that your hash is "time + payload + password", if a third party gets a copy of your payload and knows the time. It can find the password (using a brute force or dictionary attack). So, its almost as if you are sending the password in clear text.

Instead of this you should look at a public key cryptography have your server send out public keys to your agents and have the agents encrypt the data with the public key.

No man in the middle will be able to tell whats in the messages, and no one will be able to forge the messages.

On a side note, MD5 is plenty strong most of the time.

answered 2009-05-04T02:26:06.290
0

I'm not going to comment on the MD5/SHA1/etc. issue, so perhaps you'll consider this answer moot, but something that amuses me very slightly is whenever the use of MD5 et al. for hashing passwords in databases comes up.

If someone's poking around in your database, then they might very well want to look at your password hashes, but it's just as likely they're going to want to steal personal information or any other data you may have lying around in other tables. Frankly, in that situation, you've got bigger fish to fry.

I'm not saying ignore the issue, and like I said, this doesn't really have much bearing on whether or not you should use MD5, SHA1 or whatever to hash your passwords, but I do get tickled slightly pink every time I read someone getting a bit too upset about plain text passwords in a database.

answered 2009-05-08T01:36:27.873

Your Answer