> On 4/21/06, Doug Stewart <dstewart at atl.lmco.com> wrote:
>> It's quick and Relatively Good Enough for operations (like in this case)
>> whose timeframe for expiration are far shorter than the time it would
>> take to crack the hash itself.  Although, the Wikipedia article Robert
>> linked to does point out a lot of the shortcomings with MD5.  Why don't
>> we use sha1() instead?

SHA-1 has recently begun to show weaknesses. For now they're probably 
not relevant for this use case, but attacks only get better with time. 
They never get worse. SHA-256, SHA-512, or Whirlpool might be better 

