3 ms·
While MD5 hashes are insecure for hashing passwords or other sensitive data, they're still fine for verifying the integrity of data if you are simply verifying
by 2cb 6y ago
While MD5 hashes are insecure for hashing passwords or other sensitive data, they're still fine for verifying the integrity of data if you are simply verifying a file has not been corrupted.
If MD5 was being used to verify a piece of software you actually want, it's not secure as it's not collision resistant.
But since we can be quite sure no one has made a file that shares an MD5 hash with this new strain of malware, MD5 is sufficient as a checksum in this use case.
You're correct to point out that newer hashes are still preferable though, simply to get out of the habit of using MD5 if nothing else. I assume you got downvoted because MD5's weaknesses aren't relevant in this specific instance. But still they could just have easily used SHA256.