MD2 generator
MD2 in Depth
MD2 (1989, Ronald Rivest) was optimized for 8-bit microprocessors — a world of smart cards and embedded chips. It processes input through an 18-round permutation over a fixed S-box, producing a 128-bit digest at a leisurely pace by modern standards.
Why It Failed
Cryptanalysts found preimage attacks far faster than brute force, and its design predates modern hash security notions entirely. It survives in software only where something, somewhere, still verifies an MD2 checksum from the early 90s.
Bottom Line
Use it to match legacy values or study hash history. For everything else — even non-security checksums — MD5 is the weakest you should consider, and SHA-256 the default.
How to Use the MD2 Hash Generator
MD2 is one of the earliest cryptographic hashes — an 8-bit-optimised 128-bit digest from RFC 1319 (1992), kept here for historic interest and compatibility with very old systems.
- Enter the legacy checksum input — MD2 dates to 1989, so this is mainly for retro compatibility checks.
- Click the hash button to compute the 128-bit MD2 digest.
- Copy the 32-character hexadecimal result for historical research or legacy-system compatibility checks.
Example
Hashing the word hello with MD2 always produces a9046c293a3c0097e38ecf6c0d7ffcf4 — the same 32-character digest every time, just as the original 1992 specification defines.
Frequently Asked Questions
What was MD2 designed for?
Ronald Rivest designed MD2 for 8-bit computers and early email security (PEM). In the early 1990s it was a serious proposal; today it survives only as a historical curiosity.
Is MD2 secure at all?
No. Practical collision and preimage attacks exist, and its 128-bit size was already marginal decades ago. Never use MD2 for any real security purpose.
Why would anyone hash with MD2 today?
Almost nobody does — except researchers studying hash history, or engineers verifying digests produced by ancient software that still references MD2.