Secure checksums: SHA256

The recent MD5 post reminded me that of course MD5 is not a cryptographically secure checksum - it can be spoofed. Especially, when getting files from untrusted sources an MD5 checksum is not a proof of a valid file. But it is a fast algorithm that can be used for your own storage and backup needs.

A secure algorithm is the SHA256, which can be also calculated on Windows without any additional downloads.

A quick sample batch file could look like this:

@echo off
echo.
echo Running certutil...
echo.
certutil -hashfile [filepath] sha256
echo.
echo Should be SHA256:
echo BD708C0E71E75BD73C636A957451A0CC2C84D7E587AB8FC549141074EF01AF7D
echo.
pause

A more detailed discussion of pros and cons follows below:

  • MD5 (Message-Digest Algorithm 5)
    • Pros:
      • Speed and Low Overhead: Computes faster than SHA-256, making it lightweight for scanning massive drives or deduplicating huge local media libraries.
      • Compact String Length: At 32 hexadecimal characters, MD5 strings are short, easy to display in compact UI tables, and take up minimal database storage.
      • Ubiquitous Support: Supported natively across virtually every operating system, legacy tool, script, and database.
      • Sufficient for Accidental Corruption: Reliably detects non-malicious errors such as network timeouts, dropped packets, or bad disk sectors during downloads.
    • Cons:
      • Cryptographically Broken: Practical collision attacks exist. Attackers can forge a malicious executable or ISO that matches the exact MD5 hash of a legitimate file in seconds.
      • Unsafe for Supply Chain Verification: You cannot trust an MD5 checksum provided on a website to prove that a downloaded binary hasn't been backdoored by a middleman or compromised server.
  • SHA-256 (Secure Hash Algorithm 256-bit)
    • Pros:
      • Collision-Resistant Security: It is computationally infeasible to generate two distinct files with the same SHA-256 hash or to create a malicious payload that matches an existing SHA-256 checksum.
      • Tamper Proofing: Guarantees both file integrity (no corruption during transfer) and authenticity/tamper-resistance (provided the published checksum itself is trusted).
      • Modern Hardware Acceleration: Modern Intel, AMD, and ARM processors include dedicated SHA instruction sets (SHA-NI), closing the performance gap with older hash functions.
      • Modern Ecosystem Standard: Standard default across Linux package managers (APT, YUM), container registries (Docker), Git commit verification, and software vendors.
    • Cons:
      • Slightly Higher Compute Cost: Requires marginally more CPU cycles than MD5 when processing gigabyte-scale files on old hardware without SHA hardware acceleration.
      • Longer String Output: The 64-character string requires more visual real estate in documentation and logs.
  • Recommendation
    • Use SHA-256 whenever verifying software downloads, operating system ISOs, firmware updates, or anything executable.
    • Use MD5 only when working with legacy systems that do not support SHA-256, or when checking for non-malicious file duplication/bit rot on a local closed filesystem where security is not a factor.

Comments

Popular posts from this blog

SQL Server Setup: Windows Firewall warning (Ports)

SQL Server 2014: Merge Replication

Active Directory Sizing and Capacity Planning