MD2
Compute the MD2 (RFC 1319) hash of any input.
Calculate MD2 hashes of text in your browser. Legacy compatibility only. Free, offline, runs entirely client-side. Read more Show less
What is MD2?
MD2 (Message Digest 2) is a cryptographic hash function designed by Ron Rivest in 1989 for use with 8-bit computers. It produces a 128-bit (16-byte) digest. It was standardized in RFC 1319.
MD2 is cryptographically broken. Collisions and preimage attacks are practical. It survives only because it appears in a few legacy protocols (notably some older certificate signatures and the original Privacy Enhanced Mail standard). Never use it for new systems - use SHA-256 or BLAKE3 instead.
How to compute MD2
Type or paste your input. The tool hashes the raw bytes, so choose the correct input encoding (UTF-8 text, hex, or Base64). For example, the UTF-8 string abc produces:
da853b0d3f88d99b30283a69e6ded6bb
A bit about the algorithm
MD2 processes input in 16-byte blocks. It pads with bytes 1, 2, 3, ..., N where N is chosen so the total length is a multiple of 16. Then it appends a 16-byte checksum computed over the padded message. The checksum and message are then processed through a 48-byte state using an 18-round mixing function and a 256-byte S-box (a permutation table derived from the digits of ?).
The result is deterministic and platform-independent - MD2 of the same bytes is the same everywhere.
FAQ
Why would anyone still use MD2?
Legacy compatibility. Some very old certificate chains, PKCS#7 payloads, and Privacy-Enhanced Mail messages used MD2. If you have to verify one of those, you need an MD2 implementation. This tool provides one without requiring a Python or OpenSSL install.
Can MD2 be reversed?
No. Hash functions are one-way by design. You cannot recover the original input from an MD2 hash.
MD2 vs MD4 vs MD5
All three were designed by Ron Rivest. MD2 targets 8-bit processors and uses an S-box; MD4 and MD5 operate on 32-bit words and use arithmetic rounds. MD4 and MD5 are both faster than MD2. All three are broken and unsafe for new systems.
Is MD2 collision-resistant?
No. Practical collision attacks exist. Do not use MD2 where collision resistance matters.
Why is MD2 output 32 hex characters?
MD2 produces 16 bytes. Each byte is two hex characters. 16 ? 2 = 32.
Command line equivalent
# Python
python3 -c 'import hashlib; print(hashlib.new("md2", b"abc").hexdigest())'
# (may need: pip install hashlib-md2)
# OpenSSL
echo -n "abc" | openssl dgst -md2
# Node - no built-in MD2; use an npm package
npm i js-md2
node -e 'const md2 = require("js-md2"); console.log(md2("abc"))'