Tooleux

Compute the MD2 (RFC 1319) hash of any input.

Runs in your browser. Nothing leaves your device.
Calculate MD2 hashes of text in your browser. Legacy compatibility only. Free, offline, runs entirely client-side. Read more Show less

What is MD2?

MD2 (Message Digest 2) is a cryptographic hash function designed by Ron Rivest in 1989 for use with 8-bit computers. It produces a 128-bit (16-byte) digest. It was standardized in RFC 1319.

MD2 is cryptographically broken. Collisions and preimage attacks are practical. It survives only because it appears in a few legacy protocols (notably some older certificate signatures and the original Privacy Enhanced Mail standard). Never use it for new systems - use SHA-256 or BLAKE3 instead.

How to compute MD2

Type or paste your input. The tool hashes the raw bytes, so choose the correct input encoding (UTF-8 text, hex, or Base64). For example, the UTF-8 string abc produces:

da853b0d3f88d99b30283a69e6ded6bb

A bit about the algorithm

MD2 processes input in 16-byte blocks. It pads with bytes 1, 2, 3, ..., N where N is chosen so the total length is a multiple of 16. Then it appends a 16-byte checksum computed over the padded message. The checksum and message are then processed through a 48-byte state using an 18-round mixing function and a 256-byte S-box (a permutation table derived from the digits of ?).

The result is deterministic and platform-independent - MD2 of the same bytes is the same everywhere.

FAQ

Why would anyone still use MD2?

Legacy compatibility. Some very old certificate chains, PKCS#7 payloads, and Privacy-Enhanced Mail messages used MD2. If you have to verify one of those, you need an MD2 implementation. This tool provides one without requiring a Python or OpenSSL install.

Can MD2 be reversed?

No. Hash functions are one-way by design. You cannot recover the original input from an MD2 hash.

MD2 vs MD4 vs MD5

All three were designed by Ron Rivest. MD2 targets 8-bit processors and uses an S-box; MD4 and MD5 operate on 32-bit words and use arithmetic rounds. MD4 and MD5 are both faster than MD2. All three are broken and unsafe for new systems.

Is MD2 collision-resistant?

No. Practical collision attacks exist. Do not use MD2 where collision resistance matters.

Why is MD2 output 32 hex characters?

MD2 produces 16 bytes. Each byte is two hex characters. 16 ? 2 = 32.

Command line equivalent
# Python
python3 -c 'import hashlib; print(hashlib.new("md2", b"abc").hexdigest())'
# (may need: pip install hashlib-md2)

# OpenSSL
echo -n "abc" | openssl dgst -md2

# Node - no built-in MD2; use an npm package
npm i js-md2
node -e 'const md2 = require("js-md2"); console.log(md2("abc"))'
Loads a test value into the form
Input
MD2