Weak Cryptography

Weak cryptography in C#

Description

Using MD5 or SHA1 where collision resistance is required, or using DES or ECB mode for encryption, weakens cryptographic protection.

Potential impact

  • Increased risk of bypassing integrity checks, analyzing ciphertext, or decrypting data.

Remediation

Use a modern hash such as SHA-256 when collision resistance is required, and an authenticated encryption mode such as AES-GCM for encryption. Use a dedicated password hashing scheme instead of ordinary SHA-256 for password storage.

Examples

Before

csharp
using var md5 = MD5.Create();

After

csharp
using var sha256 = SHA256.Create();

Explanation:

  • Before: MD5 is unsuitable for security checks that require collision resistance.
  • After: The example replaces a general-purpose hash with SHA-256. It is not an encryption or password-storage implementation.

References