Hash Generator

Generate MD5, SHA-1, SHA-256, and SHA-512 hashes instantly.

Security
Input Text

What is a cryptographic hash function?

A cryptographic hash function takes an input of any size and produces a fixed-size output (the hash or digest) with three essential properties: it is deterministic (same input always gives same output), one-way (it is computationally infeasible to reverse the hash to recover the input), and collision-resistant (it is computationally infeasible to find two different inputs that produce the same hash).

Hash functions are used throughout software and security: to verify file integrity (a file's SHA-256 hash changes if even one bit is altered), to store passwords (you store the hash, not the plaintext — though you should use bcrypt or Argon2 for passwords, not SHA-256), to create digital signatures, to implement content-addressed storage (like Git), to generate unique identifiers from content, and to produce checksums for data integrity verification.

SHA-256 (from the SHA-2 family) is the current standard for most security applications. SHA-512 provides additional security margin for highly sensitive contexts. MD5 and SHA-1 are cryptographically broken — collision attacks have been demonstrated — and should not be used for security. They remain useful for non-security purposes like detecting accidental data corruption or generating cache keys.

Common mistakes

  • Using MD5/SHA-1 for security — MD5 and SHA-1 have known collision vulnerabilities. Use SHA-256 or SHA-512 for any security-sensitive application.
  • Hashing passwords with SHA-256 — SHA-256 is too fast for password storage — it allows billions of attempts per second on GPU hardware. Use bcrypt, Argon2, or scrypt, which are designed to be slow.
  • Hash without salt — Hashing the same password always produces the same hash, enabling rainbow table attacks. Always add a unique random salt when hashing passwords.