• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Root md5sum?

PrinceCorwin

Android Expert
When I read the thread directing me how to install the various ROMs for the spectrum, I keep seeing a direction to verify the md5sum. How do I do that?
 
BTW, thanx for all the dev and support in rooting and ROMing since the v7 ota. I've just about gotten over the horror and anxiety of my first root attempt (just after the v7 ota). I backed out and returned to stock before the bootloader was officially unlocked and haven't had the nerve to try it again. But I think I'm just about there (I desperately want to try out the CM10.1 ROM). So I'm just researching some things that I'm not familiar with to make it go as smooth as possible. So if anyone could help me out with the md5sum question, I'd really appreciate it (I know... I could just google it, but you guys always have a more direct answer than I find on the net)
 
So I just download it, run it, and it will tell me if it's verified? Am I looking for a specific value? Sorry for the noobness but I really don't know what this part of the process is all about. And thanx again for all your hard work neph. You're an android godsend!
 
Install this, then right click on any file in Windows and go down to properties. You will have a new tab called File Hashes. You can configure it to auto generate any hash types you want. You can then compare this hash to the hash provided in the thread with the original download. If you get a match, it's good. If not, try the download again.
 
verifying the md5sum is overrated and though it has a reason behind doing so it's not really that important because I've been doing things on computers for years that say to verify the md5sum and I only did it like 2 times back years and years ago when I didn't know much and thought it was required. Honestly it's not that important because 99.999 percent of the time the md5sum will be fine.

I guess it's just the laziness in me but I honestly can't be bothered to ever check a stupid md5sum, and I can attest to the fact that it's never been an issue for me. So do as me and say away with checking the md5sum and just assume it's good to go, because most of the time it is :p
 
Someone still use DSL and it works bad often. I had DSL and speed was low and many times aborted download. DSL is pain in the ass. So I can use downloader manager to cresume download. Many times resuming download overwrite file with missing offset. Must have md5sum to check properly.
 
verifying the md5sum is overrated and though it has a reason behind doing so it's not really that important because I've been doing things on computers for years that say to verify the md5sum and I only did it like 2 times back years and years ago when I didn't know much and thought it was required. Honestly it's not that important because 99.999 percent of the time the md5sum will be fine.

I guess it's just the laziness in me but I honestly can't be bothered to ever check a stupid md5sum, and I can attest to the fact that it's never been an issue for me. So do as me and say away with checking the md5sum and just assume it's good to go, because most of the time it is :p

I think I'll go with this advice, since I have absolutely no idea what Neph is talking about. His knowledge is over my head.
 
I think I'll go with this advice, since I have absolutely no idea what Neph is talking about. His knowledge is over my head.

to put it plainly, it's basically just an ID code to verify the file is not corrupted, and to verify it you just need a simple little program that you load the file into and it checks the md5sum. Just google it.

Really though it's not needed in most cases because they rarely get corrupted. I don't even have a wired internet connection being that I use my phone for all my internet needs and I've yet to have a download with a corrupted m5dsum.

Heres the simple method for noobs...if the file you downloaded isn't working right, redownload it...if the redownload doesn't work, then try one more time...if that one still doesn't work; most likely you're just a hopeless noob and need a new hobby, giving up is the wise thing to do at that point :D
 
This is monumentally bad advice.

Not having a problem in two years is like saying, I haven't had a flat tire in two years, I don't know about the roads you drive on, but you don't need a spare tire.

I can't count the number of borked situations with users crying the blues because they didn't check the MD5 sum before flashing.

I do it for every flash, and I've been saved many a time.

Check out "AFV (Android File Verifier)"

https://play.google.com/store/apps/details?id=sa.afv

Seriously, verifying before flashing is as fundamental as making nandroid backup.
 
the years and years ago was not just 2 but actually more like ten. You guys are just super geeks that like your t's crossed and i's dotted :p Point well taken though, my advice may not have been the best but my advice wasn't meant to help him with a problem so much as it was to let him know that md5sum verification isn't a life and death thing and actually can be ignored. I'm living proof that this is the case being that I haven't done a md5sum verification in ten years, and have never once suffered any bad consequences from not doing so. Sure I've had a few files that were currupted over the years, but a redownload fixed it. Perhaps I could have saved 5 minutes here and there over the years but I would have wasted 50 hours checking md5sum every time I download something.

PS. I rarely use backups either :p

PPS: I've not bricked my phone once in the year I've had it =]
 
the years and years ago was not just 2 but actually more like ten. You guys are just super geeks that like your t's crossed and i's dotted :p Point well taken though, my advice may not have been the best but my advice wasn't meant to help him with a problem so much as it was to let him know that md5sum verification isn't a life and death thing and actually can be ignored. I'm living proof that this is the case being that I haven't done a md5sum verification in ten years, and have never once suffered any bad consequences from not doing so. Sure I've had a few files that were currupted over the years, but a redownload fixed it. Perhaps I could have saved 5 minutes here and there over the years but I would have wasted 50 hours checking md5sum every time I download something.

PS. I rarely use backups either :p

PPS: I've not bricked my phone once in the year I've had it =]

come again??? you've not permantly bricked you phone you mean??? I seem to recall quite a few occasions of a soft brick. ;)
 
Yes corrupted or incomplete downloads are rather rare. I've never had one personally. But I have seen others with them. Usually they will have some strange issue that nobody else has. Sometimes a big issue sometimes a small one. Then a few posts later they admit their download was corrupted or incomplete and a fresh download fixed their issue.

Should you verify md5? Yes.

Does it normally matter? No.

If you don't verify the md5 and you have problems what's the absolute first thing you do? Verify the md5!
 
All it takes is a PC error. Lots of people get plenty of those.

There's a right way to flash, and there's a way to cut corners that some of you are ok with.

That it works often doesn't erase the fact that it's doing it wrong.

Devs provide MD5 sums for a reason.

By the time you have a bad flash, your phone may not be working, and you'll have to plug in, mount as USB storage, and then do the check from your PC. First, you'll be posting here asking what to do and what an MD5 sum is, and then where to get a pc app for that.

I've seen this countless times on our forums. And that doesn't take 5 minutes, that takes the time of a solution thread and all the confusion that entails.

All of which can be avoided if done right the first time.

And the time savings for the casual flasher is a myth when the above scenario hits just one time.

Now, if you've NEVER had a pc file error, internet error, usb cable error, file copy error or memory error, by all means, take the shortcut - or if you're ok just flashing things and finding out while you're making a call, sending a text, doing email that there's a problem where you might want to just drop what you're doing so you can re-flash your rom, and download it again if that fails - by all means, skip the simple 2 minute check with extreme confidence.

What could possibly go wrong?
 
come again??? you've not permantly bricked you phone you mean??? I seem to recall quite a few occasions of a soft brick. ;)

you recall wrongly. unless you remember something I don't, because I don't recall any soft bricks. I've had issues with things like that time twrp was killing me and every rom I installed using it ran really buggy, but I never had a bootloop or soft brick, I just had a buggy rom each time.
 
To interject, MD5 when I started using Linux was for integrity checking to make sure someone didn't unpack a file and insert some malicious code and repackage it and then distribute it, so MD5 is for security checking, I suppose it works for corruption in any form too.
I am with IMUcarmen, use to do MD5 years ago (13 or so) saw it was a waste most of the time, it is all about trust I suppose, do you trust where you download from and who you download from.
Linux/K3B has a built in MD5 checksum generator checker, makes it handy.
 
To interject, MD5 when I started using Linux was for integrity checking to make sure someone didn't unpack a file and insert some malicious code and repackage it and then distribute it, so MD5 is for security checking, I suppose it works for corruption in any form too.
I am with IMUcarmen, use to do MD5 years ago (13 or so) saw it was a waste most of the time, it is all about trust I suppose, do you trust where you download from and who you download from.
Linux/K3B has a built in MD5 checksum generator checker, makes it handy.

Malicious code injection and other forms of security breaches are just intentional forms of corruption.
 
Malicious code injection and other forms of security breaches are just intentional forms of corruption.
True. Hence why download providers picked it up as a integrity checker.
But as we speak right now MD5 is vulnerable, a hack for MD5 is out and can be spoofed (in software terms, to trick or fool a program into thinking a malicious file is valid), so MD5 is no longer secure.
SHA-2 is the thing now.
 
To interject, MD5 when I started using Linux was for integrity checking to make sure someone didn't unpack a file and insert some malicious code and repackage it and then distribute it, so MD5 is for security checking, I suppose it works for corruption in any form too.
I am with IMUcarmen, use to do MD5 years ago (13 or so) saw it was a waste most of the time, it is all about trust I suppose, do you trust where you download from and who you download from.
Linux/K3B has a built in MD5 checksum generator checker, makes it handy.

MD5 was broken for that sort of use in 1996.

For checking rom downloads, it's perfectly fine.

And to say it's about crypto use and just trusting the download source simply means that you trust things in the entire data path.

I started using checksums in the early 80s to verify satellite data transfers and have yet to be convinced that it's a bad idea to verify file transfers. ;) :)
 
MD5 was broken for that sort of use in 1996.

For checking rom downloads, it's perfectly fine.

And to say it's about crypto use and just trusting the download source simply means that you trust things in the entire data path.

I started using checksums in the early 80s to verify satellite data transfers and have yet to be convinced that it's a bad idea to verify file transfers. ;) :)
To me when something is broken to the point it is useless then it is just that. My$.02
To say ROMs are fine but I won't trust it for something else makes no sense to me.:confused:
Checking for the sake of checking? :D Back in dial up days sure 100% believe that you should check files, data integrity from servers has gotten much better as download speeds have increased.
I too would check data as precious as satellite (aren't they like slower data transfer than dial up?), by all means.
Not saying data integrity checking is not a bad idea, just it is not a necessity and with a spoofable algorithm quite likely it could be malicious and still pass.
Do, don't, up to the user, but all facts need to be present for a user to access if it is necessary for them or not. :)
 
md5 is not useless any more than it was before it was "broken".

When researchers say that it was "broken", it means that they found a way to drastically increase the odds of maliciously injecting arbitrary data into a file while hasing to the same md5. It is still quite difficult to accomplish.

There are many, many possible files of a given size that will hash to the same md5 or sha. It's just a matter of odds.

If you trust that nobody is trying to maliciously infect your file, the odds of a corrupt file with a matching md5 are astronomically low just as they always have been. The odds are not zero. They never have been and never will be with any hash, no matter how "secure". That's the nature of a hash.

If you don't have that trust, you shouldn't be using Android. It's full of insecure code. After all, how did you get your phone rooted in the first place? ;)
 
Great academic discussion.

Recap - wealth of threads here substantiate that checking roms before flashing is a good thing and many accepting this as a best practice

Vs.

Anecdotes about how it hasn't happened to some therefore it won't happen to others, and this does no good.

In the science biz we have a saying - if your theory doesn't match the data, you can throw out your theory or throw out the data that displeases you.

Have a fantastic day! :)
 
you recall wrongly. unless you remember something I don't, because I don't recall any soft bricks. I've had issues with things like that time twrp was killing me and every rom I installed using it ran really buggy, but I never had a bootloop or soft brick, I just had a buggy rom each time.

you may be right, you always sat back and let some one else pull the trigger first. :p


But personally I only check the md5sum or what ever may be used if I dont trust who/where its coming from. I provide the md5sum for those who want to check it or dont trust me or anyone/thing.
 
Back
Top Bottom