☕

Hash Generator

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes from text or a file, in hex or base64, and compare a result against an expected checksum. Nothing is uploaded.

Helpful?

Digests

MD5not secureBroken since 2004. Checksums only, never security.
SHA-1not secureCollisions demonstrated in 2017. Legacy use only.
SHA-256The sensible default for almost everything.
SHA-384Truncated SHA-512, common in TLS suites.
SHA-512Faster than SHA-256 on 64 bit hardware.

Verify against an expected checksum

Paste the hash published alongside a download. Whichever algorithm matches is highlighted above.

Hash Generator: Digests, Checksums and What Each Algorithm Is For

What a Hash Function Does

A cryptographic hash turns any input into a fixed length digest. SHA-256 always produces 256 bits, whether you feed it one letter or a film. The same input always gives the same output, which is what makes digests comparable.

Good hash functions show the avalanche effect: changing one bit of input flips about half the output bits. That is why two nearly identical files produce completely unrelated digests, and why a digest is useful for spotting any change at all.

They are one way by design. Given a digest there is no method to reconstruct the input short of guessing. Sites that appear to reverse MD5 are searching precomputed tables of common inputs, not inverting the function.

Three properties matter: it should be infeasible to find an input for a given digest, to find a second input matching a known one, or to find any two inputs sharing a digest. That last property is where MD5 and SHA-1 have fallen.

The Five Algorithms Compared

MD5 produces 128 bits and dates from 1992. It is fast and thoroughly broken, surviving only in non adversarial roles such as ETags, cache keys and file deduplication.

SHA-1 produces 160 bits. Practical collisions were demonstrated in 2017 and browsers stopped accepting SHA-1 certificates years before that. Git still uses it for object addressing, which is a compatibility decision rather than a security one.

SHA-256 produces 256 bits and is the sensible default for essentially everything: certificates, signatures, blockchains and integrity checks alike.

SHA-384 and SHA-512 come from the same family with larger internal state. Counterintuitively SHA-512 is often faster than SHA-256 on 64 bit processors, because it works in 64 bit words.

Why MD5 and SHA-1 Are Broken

Broken means collisions are findable. Researchers produced two different inputs with the same MD5 digest in 2004, and by 2008 a team had forged a certificate authority certificate using the technique. Today an MD5 collision takes seconds on a laptop.

SHA-1 fell in 2017, when Google and CWI produced two different PDF files sharing a digest. The attack was expensive then and has grown far cheaper since.

It matters when an adversary is involved. If someone can craft both documents, they can have you sign one and substitute the other. If you are simply checking that a download was not corrupted in transit, MD5 still detects that fine.

They are still not equally broken. Neither is reversible, and finding an input matching a specific existing digest remains infeasible. The break is in creating pairs, which is why the practical guidance is to stop using them for signatures and certificates.

Verifying a Download

Publishers list a digest beside the file. Hash your copy and compare. If they match byte for byte you have exactly what was published; if they differ, something changed in transit or on disk.

Use the file mode above. The file is read into memory and hashed locally, so even a large installer never leaves your machine. Paste the published digest into the verify box and the matching algorithm is highlighted for you.

The checksum must come from a trustworthy place. If an attacker controls the page hosting both the file and its digest, they can update both. Signed checksum files and digests published on a separate domain are meaningfully stronger.

Case and spacing do not matter. Hex digests are compared case insensitively, and the verify box strips whitespace, so you can paste straight from a checksum file.

Never Hash Passwords This Way

Speed is the problem. These algorithms are built to be fast, which is exactly wrong for passwords. Modern hardware computes billions of SHA-256 digests per second, so an attacker with a leaked table tries every plausible password in hours.

Use a password hashing function instead. Argon2id is the current recommendation, with bcrypt and scrypt as solid alternatives. They are deliberately slow and memory hungry, and they handle salting for you.

Salt and pepper are not enough on their own. A salt stops precomputed rainbow tables but does nothing about raw speed. A fast hash with a salt is still a fast hash.

For message authentication, use HMAC, not a bare hash of a secret concatenated with a message. That naive construction is vulnerable to length extension attacks against SHA-256 and SHA-1.

Hex, Base64 and Why They Differ

A digest is bytes, not text. Both hex and base64 are ways of writing those bytes down. The underlying value is identical, which is why switching the toggle above does not recompute anything.

Hex uses two characters per byte, so SHA-256 becomes 64 characters. It is the conventional form for checksums and the one nearly every tool prints.

Base64 packs three bytes into four characters, giving 44 characters for SHA-256. It is common in HTTP headers, subresource integrity attributes and JSON payloads where compactness helps.

Comparing across encodings fails. A hex digest will never equal a base64 one as strings, even when they describe the same bytes. Convert before comparing.

Everyday Uses Beyond Security

Deduplication. Backup systems and object stores hash content to spot identical files without comparing them byte by byte. MD5 is common here and perfectly adequate, since nobody is attacking a backup index.

Cache keys and ETags. Hashing a response body produces a short stable identifier for it, letting a browser ask whether anything changed instead of downloading it again.

Content addressing. Git names every object by the hash of its contents, which is what makes a repository tamper evident and lets any two clones agree on what they hold.

Change detection in builds. Hashing inputs lets a build system skip work whose result is already known, which is the foundation of most modern build caches.

Frequently Asked Questions

On password storage: None of these algorithms is suitable for hashing passwords, however you salt them. Use Argon2id, bcrypt or scrypt, which are designed to be slow enough that mass guessing stops being practical.

Check out our other tools

Browse all tools