Description
MD5 and SHA-1 are vulnerable to collision attacks. Do not use them for integrity checks or data identifiers that require collision resistance. Password storage additionally needs a hashing design that slows offline guessing; collision resistance alone is insufficient.
Potential impact
- Integrity-check bypass
- Increased risk of forged tokens or authentication data
- Weaker password storage
Remediation
- Use SHA-256, SHA-512, or SHA-3 for security-sensitive general hashing.
- Use a password-specific algorithm such as Argon2id, bcrypt, scrypt, or PBKDF2 to store passwords.
- Keep legacy MD5/SHA-1 compatibility code separate from security decisions.
Examples
Before
swift
let digest = Insecure.MD5.hash(data: tokenData)
After
swift
import Foundation
import CryptoKit
func hashToken(_ tokenData: Data) -> SHA512.Digest {
return SHA512.hash(data: tokenData)
}
Explanation:
- Before: An MD5 digest used as an identifier does not provide strong collision resistance.
- After: SHA-2 or SHA-3 is suitable for an identifying digest of a token with sufficient entropy. Passwords need Argon2id, scrypt, bcrypt, or PBKDF2 rather than a fast hash such as SHA-512.