Hash functions and their outputs
A cryptographic hash function turns input of any size into a short, fixed-size value called a hash or digest. Hashes are used for password storage, digital signatures, file integrity checks and much of modern security.
Hashing is not encryption. Encryption can be reversed with the right key; a hash is designed to be one-way, so there is no practical way to get the original input back from the digest.
Key properties
Deterministic
The same input always gives the same hash. That is what makes a hash useful for checking that two things match.
Fast to compute
Hashing produces a digest you can compare with a known value. The time needed depends on the algorithm and input size.
Pre-image resistance
Given a hash, it should be infeasible to find any input that produces it.
Collision resistance
It should be infeasible to find two different inputs that produce the same hash.
Avalanche effect
Changing a single character changes many bits of the output. Try adding a full stop to the sample text above and watch every hash change.
The algorithms on this page
| Algorithm | Output | Hex length | Status |
|---|---|---|---|
| MD5 | 128 bits | 32 | Broken. Fine for checksums, not for security. |
| SHA-1 | 160 bits | 40 | Broken. Practical collisions shown in 2017. |
| SHA-256 | 256 bits | 64 | Secure. The usual default. |
| SHA-384 | 384 bits | 96 | Secure. |
| SHA-512 | 512 bits | 128 | Secure. Often faster than SHA-256 on 64-bit CPUs. |
Base64 is included for convenience but is not a hash. It is a reversible encoding that represents bytes using 64 printable characters, which makes binary data safe to send through text-only channels such as email, JSON or URLs.
This tool hashes the UTF-8 bytes of your text, which is what most programming languages and command-line tools do. For example, echo -n "abc" | md5sum gives 900150983cd24fb0d6963f7d28e17f72, the same as typing abc here. Watch out for trailing newlines: echo without -n adds one, which changes the hash.
Verifying a hash
Paste a hash into the verify box and the tool checks it against every algorithm at once, highlighting the one that matches. If nothing matches, it uses the length to suggest which algorithm the hash probably came from, which helps when you are not sure what a download page or API used.
Where hashes are used
- Password storage: systems store a hash rather than the password. Use a slow, salted algorithm built for this (bcrypt, scrypt or Argon2), not a plain SHA-256.
- Data integrity: publishers list the SHA-256 of a download so you can check the file wasn't corrupted or tampered with.
- Digital signatures: the message is hashed and the hash is signed, which is faster than signing the whole message.
- File identification: hashes make good fingerprints for deduplication and caching, and Git identifies every commit and file by its hash.
- Blockchains: Bitcoin links blocks together and runs its proof-of-work using SHA-256.