czay.dev
Writing

The Weakest Link in Your System: The MD5 Fallacy and Secure Password Hashing

Storing passwords in plain text or with MD5 in your database is a massive mistake. To prevent password cracking that takes seconds with rainbow tables, we have to accept that speed is a vulnerability.

Furkan ÖzaySeptember 18, 2026 · 3 min read
The Weakest Link in Your System: The MD5 Fallacy and Secure Password Hashing

What is the weakest link in your system? Is it your database, or your encryption architecture? No, most of the time, the biggest weakness is your password hashing architecture itself. Storing a user's password in plain text (such as "123456") compromises the entire system.

The MD5 Fallacy

Storing passwords by "hashing" them is obviously necessary, but using legacy algorithms like MD5 doesn't protect you—it only provides a false sense of security. Algorithms like MD5 were intentionally designed to run extremely fast. That speed is a massive advantage for an attacker. Thanks to huge Rainbow Tables freely available across the internet, billions of MD5-hashed passwords can be reversed and cracked in seconds. The cracking time is literally around 0.01 seconds.

The Solution: Salt and Bcrypt

The fix to this problem is simple: The same password must produce a different result. A completely random salt is added to each user's password. This way, even if two users choose the exact same password ("admin123"), the values stored in the database are entirely different. This method renders precomputed Rainbow Tables completely useless.

Yet salt alone isn't enough. Speed is a vulnerability. For instance, SHA-256 can generate tens of billions of hashes per second—which is still fantastic speed for an attacker. Bcrypt, on the other hand, is deliberately slowed down to ensure security. An extra 200-millisecond delay on the server side won't burden your system or a regular user, but it stretches an attacker's job—who needs to run billions of guesses—across years, or even centuries.

Engineering Standards

Real engineering standards come down to a few simple rules:

  1. Do not use MD5 or SHA. The standard for password storage requires algorithms like Bcrypt, Argon2, or PBKDF2. Bcrypt is the de facto standard across most languages.
  2. Do not add manual salts. Don't try to roll your own hashing scheme by appending arbitrary strings. Bcrypt already handles salting internally.
  3. Do not invent your own algorithm. The "roll your own" concept does not fly in the security world. Rely on proven industry standards.

Note: Forgot Password Emails

If a system's "Forgot Password" feature ever emails you your old password in plain text, that system is storing your passwords in plain text (or in a reversible format). That is a massive red flag for its architecture!

Wrapping Up

The security of your data starts with sound architecture. You shouldn't know the user's password either (including system administrators). Slow your data down on purpose and cut attackers off at the knees!