Skip to main content

2026-02-20

7 min

By Formatho Editorial

Understanding Cryptographic Hashes: MD5, SHA-1, SHA-256

CryptographyHashingSecurity
Programming code showing text case formatting

What a hash is

A cryptographic hash maps any input to a fixed-size fingerprint (SHA-256: 32 bytes) with three properties: the same input always yields the same digest; the tiniest input change flips about half the output bits (avalanche); and it's infeasible to reverse or to find two inputs with the same digest (collision resistance). Hashing is one-way — unlike encryption, there is no key and no decryption.

Choose by threat model

AlgorithmStatusUse for
MD5Brokenchecksums for corruption only — never security
SHA-1Broken (collisions demonstrated)legacy compat only
SHA-256 / SHA-512Secureintegrity, signatures, digests
SHA-3Securealternative construction, different internals
HMAC-SHA256Securekeyed integrity: proves the sender holds the key
bcrypt / Argon2idSlow by designpassword storage — the only right answer there

Hashing passwords: the special case

Fast hashes are wrong for passwords: a GPU tries billions of SHA-256 guesses per second, so any 8-character password falls in hours. Password hashing must be deliberately slow and memory-hard — bcrypt (cost factor) or Argon2id (memory + time + parallelism parameters), with a unique salt per user so identical passwords hash differently and precomputed rainbow tables are useless. Never store passwords with MD5/SHA-anything, and never "pepper" instead of salting.

Verifying downloads and more

The everyday use: a site publishes sha256sum installer.bin; you run the same command locally and compare digests — any mismatch means corruption or tampering. Same mechanism powers content addressing (git objects, container layer digests, Subresource Integrity in CSP headers) and deduplication.

Common mistakes

  • Comparing digests with non-constant-time equality in security contexts — use a constant-time compare.
  • Concatenating fields before hashing without a separator: hash("ab" + "c") == hash("a" + "bc") — length-prefix or delimiter.
  • Trusting a hash from the same channel as the file — the checksum must arrive via a separate, authenticated path.

Compute SHA-256/SHA-3/MD5 digests of any text or file in the Hash tool — client-side, nothing uploaded.

Formatho Editorial — written and maintained by the team behind formatho.com, a library of free, privacy-first developer tools that run entirely in your browser. Every guide is tested against the tools it describes. Corrections and suggestions: github.com/formatho.