Hash algorithms compared
A hash is a fixed-length fingerprint of data. The same input always gives the same hash, but a tiny change, even one
letter, produces a completely different result, and you can't work backwards from the hash to the input.
Frequently asked questions
Which hash should I use?
Use SHA-256 for checksums and general integrity checks; it's the modern standard. SHA-512 is also secure. MD5 and SHA-1 are broken for security purposes but are still used to compare files and in older systems, so they're included for compatibility.
How do I check a downloaded file's checksum?
Choose the file, pick the algorithm the website lists (usually SHA-256), and compare the result with the published checksum. If even one character differs, the file is corrupted or has been changed.
Should I hash passwords with SHA-256?
No. General-purpose hashes are designed to be fast, which makes them easy to brute-force. Store passwords with a slow, salted algorithm such as Argon2, bcrypt or scrypt instead.
What is HMAC?
HMAC combines a hash with a secret key to create a signature, proving that a message came from someone who knows the key and wasn't changed. It's used by APIs and webhooks such as GitHub's and Stripe's to sign requests.
Are my files uploaded?
No. Text and files are hashed in your browser. Even large files are read only on your device.