EMZETT.
Login

SHA-128

In short: No standard algorithm with exactly 128 bits of output length exists in the official SHA family — this term presumably refers to another, shorter hash type used to distinguish it from SHA-256/SHA-512 in the SHA-types overview.

In more detail: The actual SHA standards are SHA-1 (160 bits, outdated), SHA-224, SHA-256, SHA-384 and SHA-512 (SHA-2 family), as well as SHA3-224 through SHA3-512 (SHA-3 family, different internal construction). A 128-bit hash is in practice usually associated with MD5 (128 bits, cryptographically broken, no longer suitable for security purposes). For a reliable answer on the exact source of this term, it’s worth checking against the chamber-of-commerce course-material overview of SHA variants.

In Depth

The confusion around “SHA-128” probably comes from the fact that SHA output lengths look at first glance like a continuous sequence (128, 160, 256, 384, 512 bits), but in reality each family has its own, historically grown variants:

MD5     - 128 bit  (not SHA, cryptographically broken, do not use securely)
SHA-1   - 160 bit  (SHA family, practically broken since 2017)
SHA-256 - 256 bit  (SHA-2 family, current standard)
SHA-384 - 384 bit  (SHA-2 family)
SHA-512 - 512 bit  (SHA-2 family)

Anyone who explicitly needs a 128-bit hash (e.g. for compatibility reasons with an old system) in practice almost always ends up with MD5 — with the important caveat that MD5 is unsuitable for any security-relevant purpose (passwords, signatures, certificates), since collisions can be deliberately produced. For non-security-critical purposes (e.g. a quick checksum to detect random file corruption), MD5 remains in common use, simply because it’s very fast.

If this term comes from a specific piece of course material that actually calls “SHA-128” a standalone algorithm, it’s probably a simplified or imprecise label for one of the algorithms mentioned above — when in doubt, it’s worth asking the source which concrete algorithm was meant.

Why MD5 still exists despite being insecure

Although MD5 has been considered cryptographically broken since the 2000s (in 2004 Chinese researchers demonstrated practically feasible collisions), the algorithm hasn’t disappeared entirely from practice — it’s still used in contexts that are NOT about protection against deliberate manipulation, but only about quickly detecting random errors: some legacy systems use MD5 checksums to detect transmission errors when copying files, or as a fast (non-security-critical) cache key under which content can be uniquely identified. For any purpose where an attacker could actively try to produce a collision (signatures, certificates, passwords), MD5 is categorically unsuitable, however.

The general confusion around hash names

A recurring misconception with hash algorithms is the assumption that the number in the name always corresponds exactly to a sequential generation number — in reality it almost always denotes the output length in bits, not a version number. This leads to seemingly illogical jumps (SHA-1 at 160 bits, then straight to SHA-256 at 256 bits, no “SHA-2” with 128 or 192 bits), and explains why a term like “SHA-128” can easily seem plausible even though it doesn’t actually exist in any official standard.

Practical consequence

Anyone facing the decision today of which hash algorithm to use in their own project should follow a simple rule of thumb: for anything security-relevant (password hashing, signatures, integrity checking of downloads), SHA-256 currently counts as a solid standard, with SHA3-256 as a more modern alternative with a structurally different internal construction (making it independent of any potential future weaknesses in the SHA-2 construction). For pure password hashing, specialised algorithms like bcrypt, scrypt or Argon2 are even better suited than a plain SHA hash, since they’re deliberately built to be slow and memory-intensive, to massively slow down automated guessing (brute force) — a simple, very fast SHA-256 hash is actually a disadvantage for this specific purpose, because it makes mass guessing easier for attackers.

See also: SHA types, Hashing