Description
MD5 and SHA-1 are unsuitable for security hashes that require collision resistance. DES and RC4 must not be used to encrypt new data.
Potential impact
- Password cracking, signature bypass, or ciphertext decryption may become easier.
Remediation
Use SHA-256 or stronger for general security hashing and a vetted AEAD scheme for encryption. Store passwords with a dedicated password-hashing scheme such as Argon2id, bcrypt, or PBKDF2, using a salt and an appropriate work factor.
Examples
Before
c
unsigned char out[MD5_DIGEST_LENGTH];
MD5(data, len, out);
After
c
unsigned char out[SHA256_DIGEST_LENGTH];
SHA256(data, len, out);
Explanation:
- Before: MD5 is used for a security hash.
- After: MD5 is replaced with SHA-256. A single SHA-256 call does not replace password hashing or data encryption.