What a hash is and what it is for

A hash function turns data of any length into a fingerprint of fixed length: 128 bits for MD5, 256 for SHA-256. Changing a single letter changes the fingerprint completely, and there is no way back from the fingerprint to the data.

That is why hashes are used to check that a download is intact, to identify data without keeping it, to sign documents and, with slow algorithms and salt, to store passwords. Git names every version with a SHA-1; Bitcoin rests on SHA-256.

MD5 and SHA-1 are no longer secure: two different files with the same fingerprint can be built on purpose. They are still useful against transmission errors, but security needs SHA-256 or stronger.

Common mistakes

  • Comparing a hash computed on a text with an extra line break or space: one invisible character changes everything.
  • Storing passwords with plain MD5 or SHA-256: they are too fast to try in bulk. Slow algorithms like bcrypt or Argon2 are needed.
  • Thinking a hash can be decrypted: it is not encryption. Sites that 'reverse' hashes only look them up in tables of precomputed ones.

Frequently asked questions

Can I get the text back from its hash?

No. A good hash function cannot be inverted; one can only guess the text and compare. That is why short or common passwords are found anyway.

How do I check a downloaded file?

Compute the file's hash with a system tool (sha256sum on Linux, Get-FileHash on Windows) and compare it with the published one. If a single character differs, the file is different.

Why does the same text give different hashes in different programs?

Usually because of the encoding or the line endings: a text saved with CRLF or in Latin-1 has different bytes from the same text in UTF-8 with LF, and so a different hash.

How this calculation works

The text is first turned into bytes with UTF-8. SHA-1, SHA-256, SHA-384 and SHA-512 are computed with the browser's Web Crypto API, following FIPS 180-4. MD5 follows RFC 1321: the data are padded to a multiple of 512 bits with their length, then each block goes through 64 steps of additions, rotations and logical functions on four 32-bit words.