A hash function takes any input — a password, a file, a block of text — and turns it into a fixed-length string of characters that acts as a unique fingerprint. Change even a single character of the input and the output hash changes completely. That property is what makes hashes useful for verifying data integrity and storing passwords securely, but not every hash algorithm is equally trustworthy anymore.

What a Hash Function Does

Feed the same input into the same hash algorithm and you'll always get the same output. Feed in different input — even a single flipped character — and the output should look completely different and unpredictable, with no obvious relationship to the original change. This makes hashes ideal for two things: confirming that a file or message hasn't been altered (by comparing hashes before and after), and storing password verification data without ever storing the actual password.

Why MD5 and SHA-1 Are Considered Broken

MD5 (1992) and SHA-1 (1995) were once the standard choices, but both have since been shown to have practical collision vulnerabilities — meaning security researchers have demonstrated real, deliberately-crafted inputs that produce the same hash despite having completely different content. For a hash meant to guarantee uniqueness, that's a fundamental failure. Neither should be used anymore for passwords, digital signatures, SSL certificates, or verifying that a file hasn't been maliciously modified. They're still commonly seen for lightweight, non-adversarial checks, like confirming a large file downloaded without random corruption — but that's about the extent of their remaining legitimate use.

Tip: If you see MD5 or SHA-1 being used for password storage in any system, that's a real red flag — modern practice uses purpose-built password hashing algorithms (like bcrypt or Argon2) that are deliberately slow to resist brute-force attacks, not general-purpose hashes like these.

When to Use SHA-256

SHA-256 (part of the SHA-2 family) is the current practical standard for general-purpose hashing — it has no known practical collision vulnerabilities, and it's the algorithm behind things like Bitcoin's proof-of-work, TLS certificate fingerprints, and most modern file-integrity checks. SHA-512 offers a longer output and slightly different performance trade-offs, but for most everyday purposes SHA-256 is the reasonable, well-supported default.

Verifying a File Wasn't Corrupted or Tampered With

Software downloads are often published alongside a hash value. After downloading, you hash the file yourself and compare it to the published value — an exact match confirms the file arrived intact and matches what the publisher actually released; a mismatch means something changed, whether through corruption or interference, and the file shouldn't be trusted.

Generating a Hash Instantly

To generate or compare a hash, paste text or upload a file into our free Hash Generator. It supports MD5, SHA-1, SHA-256, SHA-384, and SHA-512, and shows results in both hex and Base64.

FAQ

Is MD5 safe to use? Not for anything security-sensitive. MD5 has known collision attacks — meaning two different pieces of data can be crafted to produce the same hash — which makes it unsuitable for password storage, digital signatures, or verifying that a file hasn't been maliciously tampered with. It's still fine for simple, non-adversarial uses like detecting accidental file corruption during a transfer.

Why do two files with completely different content sometimes need to be checked for the exact same hash? That's not how it works — a proper hash function should give different outputs for different inputs. A hash collision, where two different inputs produce the same output, is exactly the flaw that makes MD5 and SHA-1 unsuitable for security purposes. The whole point of checking a hash is that two files with the same content will always produce the same hash, and (with a strong algorithm) different content essentially never will.

Can a hash be reversed to recover the original data? No — a cryptographic hash function is a one-way operation by design. There's no mathematical way to work backward from a hash to the original input. This is exactly why hashes (rather than the plain data) are used to verify passwords and file integrity: the hash can confirm a match without ever needing to store or expose the original value.

What's the difference between a hash and encryption? Encryption is reversible — anyone with the right key can decrypt ciphertext back into the original data. Hashing is one-way and irreversible by design, producing a fixed-length fingerprint used to verify data matches or hasn't changed, not to hide and later recover it.

Need to hash something right now? Try the free Hash Generator — MD5 through SHA-512, entirely in your browser.