Secure checksums: SHA256
The recent MD5 post reminded me that of course MD5 is not a cryptographically secure checksum - it can be spoofed. Especially, when getting files from untrusted sources an MD5 checksum is not a proof of a valid file. But it is a fast algorithm that can be used for your own storage and backup needs.
A secure algorithm is the SHA256, which can be also calculated on Windows without any additional downloads.
A quick sample batch file could look like this:
@echo off
echo.
echo Running certutil...
echo.
certutil -hashfile [filepath] sha256
echo.
echo Should be SHA256:
echo BD708C0E71E75BD73C636A957451A0CC2C84D7E587AB8FC549141074EF01AF7D
echo.
pause
A more detailed discussion of pros and cons follows below:
- MD5 (Message-Digest Algorithm 5)
- Pros:
- Speed and Low Overhead: Computes faster than SHA-256, making it lightweight for scanning massive drives or deduplicating huge local media libraries.
- Compact String Length: At 32 hexadecimal characters, MD5 strings are short, easy to display in compact UI tables, and take up minimal database storage.
- Ubiquitous Support: Supported natively across virtually every operating system, legacy tool, script, and database.
- Sufficient for Accidental Corruption: Reliably detects non-malicious errors such as network timeouts, dropped packets, or bad disk sectors during downloads.
- Cons:
- Cryptographically Broken: Practical collision attacks exist. Attackers can forge a malicious executable or ISO that matches the exact MD5 hash of a legitimate file in seconds.
- Unsafe for Supply Chain Verification: You cannot trust an MD5 checksum provided on a website to prove that a downloaded binary hasn't been backdoored by a middleman or compromised server.
- SHA-256 (Secure Hash Algorithm 256-bit)
- Pros:
- Collision-Resistant Security: It is computationally infeasible to generate two distinct files with the same SHA-256 hash or to create a malicious payload that matches an existing SHA-256 checksum.
- Tamper Proofing: Guarantees both file integrity (no corruption during transfer) and authenticity/tamper-resistance (provided the published checksum itself is trusted).
- Modern Hardware Acceleration: Modern Intel, AMD, and ARM processors include dedicated SHA instruction sets (SHA-NI), closing the performance gap with older hash functions.
- Modern Ecosystem Standard: Standard default across Linux package managers (APT, YUM), container registries (Docker), Git commit verification, and software vendors.
- Cons:
- Slightly Higher Compute Cost: Requires marginally more CPU cycles than MD5 when processing gigabyte-scale files on old hardware without SHA hardware acceleration.
- Longer String Output: The 64-character string requires more visual real estate in documentation and logs.
- Recommendation
- Use SHA-256 whenever verifying software downloads, operating system ISOs, firmware updates, or anything executable.
- Use MD5 only when working with legacy systems that do not support SHA-256, or when checking for non-malicious file duplication/bit rot on a local closed filesystem where security is not a factor.
Comments
Post a Comment