Git 3.0 will make SHA-256 the new default content hashing algorithm and it will be an incomprehensibly expensive and ultimately valueless and avoidable global nightmare.
I still like md5 for collision detection, but every damn security scanner flags it. So then you have to add the exception, then explain to auditors about the exception. It’s not worth the hassle for the increased performance.
There’s no reason to use md5 if you don’t care about security and only want speed. Non-cryptographic hashes are incredibly fast to calculate and there are far faster hashing algorithms if you want to go that route. Using md5 is a “I don’t want to think hard” answer, and if you don’t want to think hard, then you might as well be secure in your default answer.
I still like md5 for collision detection, but every damn security scanner flags it. So then you have to add the exception, then explain to auditors about the exception. It’s not worth the hassle for the increased performance.
There’s no reason to use md5 if you don’t care about security and only want speed. Non-cryptographic hashes are incredibly fast to calculate and there are far faster hashing algorithms if you want to go that route. Using md5 is a “I don’t want to think hard” answer, and if you don’t want to think hard, then you might as well be secure in your default answer.