5 ms·MD5 is not the problem here, SHA1 is also vulnerable to the extension attack. They should use HMAC.by juli 17y agoMD5 is not the problem here, SHA1 is also vulnerable to the extension attack. They should use HMAC.