What a hash function is
A cryptographic hash function takes input of any size — a word, a document, a multi-gigabyte disk image — and produces a fixed-length result called a digest or simply a hash. SHA-256, for example, always returns 256 bits, written as 64 hexadecimal digits. To be useful for security, the function has to have four properties:
- Deterministic: the same input always produces the same hash, on any machine and in any language.
- Avalanche effect: a tiny change to the input changes the output completely.
Hello, worldandHello, world.(with a trailing period) produce SHA-256 hashes with no visible relationship to each other. - One-way: there's no practical way to reconstruct the input from the hash; all you can do is try inputs until one matches.
- Collision-resistant: finding two different inputs with the same hash has to be infeasible.
That last property is what separates current algorithms from obsolete ones.
The algorithms and where they stand
| Algorithm | Size | Hex digits | Status |
|---|---|---|---|
| MD5 | 128 bits | 32 | Broken: practical collisions since 2004 |
| SHA-1 | 160 bits | 40 | Broken: first public collision in 2017 (SHAttered) |
| SHA-256 | 256 bits | 64 | Secure; today's de facto standard |
| SHA-384 | 384 bits | 96 | Secure; a truncated variant of SHA-512 |
| SHA-512 | 512 bits | 128 | Secure; often faster than SHA-256 on 64-bit CPUs |
"Broken" means you can manufacture two different inputs with the same hash. MD5 and SHA-1 still work for catching accidental errors (a corrupted download, a duplicate file), but not for anything where an attacker gets to choose the content: digital signatures, certificates, or verifying software against tampering. That's why the tool flags them as insecure. The story of those breaks, and what to use where, is in MD5, SHA-256, and bcrypt: Which Hash Function to Use for What.
How to use the tool
- Text: the text is converted to bytes using UTF-8 before hashing, just like
sha256sum, Python, or Node.js do. That's whyñgives the same result here as on any other modern system. - File: pick a file from your machine and all five hashes are computed. The file is read entirely into your browser's memory, never uploaded to a server, and hashing works offline once the page has loaded.
- Expected hash: paste the checksum published by the download site and the tool tells you which algorithm it matches. It accepts uppercase, a
sha256:prefix, and a full line from aSHA256SUMSfile (hash followed by file name). - HMAC key: if you enter a key, the tool computes an HMAC (RFC 2104) — which mixes the key with the content — instead of a plain hash. It's what webhooks and many APIs use to sign messages. HMAC-MD5 isn't available because the browser's cryptographic API doesn't support it.
Verifying a download, step by step
- On the download page, copy the published SHA-256 hash for the file (sometimes in a separate file called
SHA256SUMSor.sha256). - Select the downloaded file in the tool and paste the hash into "Expected hash."
- If it matches, the file is bit-for-bit identical to the one the site published. If it doesn't, the download is corrupted or it isn't the same file — don't use it.
One important caveat: a checksum only protects as much as the channel you got it from. If an attacker controls the download server, they can swap the file and the checksum at the same time. That's why serious projects also sign the checksum file with GPG or publish the hash through a separate channel.
The same check from a terminal:
| System | Command |
|---|---|
| Linux | sha256sum file.iso |
| macOS | shasum -a 256 file.iso |
| Windows (cmd) | certutil -hashfile file.iso SHA256 |
| Windows (PowerShell) | Get-FileHash file.iso -Algorithm SHA256 |
What a fast hash is not for
MD5, SHA-1, and the SHA-2 family are designed to be fast: a modern GPU computes tens of billions of SHA-256 hashes per second. That speed is a virtue when verifying files and a serious flaw when storing passwords. If a database stores SHA-256(password) and leaks, an attacker can run entire dictionaries against it in minutes. Passwords belong in slow, salted functions with a tunable cost, like Argon2id, scrypt, or bcrypt. The hashing guide explains why, and How to Create Strong Passwords: Entropy Explained covers the other side of the problem: how much entropy the password itself needs.
Privacy
Hashes are computed in your browser using the Web Crypto API (SHA) and a built-in implementation of RFC 1321 (MD5), verified against the official test vectors. Your text, files, and HMAC key never leave your machine.