ParentFull threaddward·HMACs do not require collision resistance from the underlying hash to provide secure message authentication. HMAC-MD5 is still considered "secure", although that doesn't mean you should use it.http://cseweb.ucsd.edu/~mihir/papers/hmac-new.pdfView on HN