MD5, SHA-1 and SHA-256 — Which Hash Should You Use?

hashsecuritysha256

A hash function turns any input into a fixed-size string of characters. The same input always produces the same hash, and even a tiny change to the input produces a completely different result. Hashes are used for checksums, password storage, and data integrity.

The common algorithms

  • MD5 produces a 128-bit hash. It is fast but cryptographically broken and should not be used for security.
  • SHA-1 produces a 160-bit hash. It is also considered weak and is being phased out.
  • SHA-256 produces a 256-bit hash and is the safe default for most modern use cases.
  • SHA-512 is a larger variant of the SHA-2 family and is useful when more output bits are wanted.

Hashing is not encryption

Encryption can be reversed with a key, while a good hash is one-way. That is why passwords should be stored as salted hashes rather than encrypted text.

Generating hashes in code

JavaScript:

const data = new TextEncoder().encode('hello')
const digest = await crypto.subtle.digest('SHA-256', data)
console.log([...new Uint8Array(digest)].map(b => b.toString(16).padStart(2, '0')).join(''))

Python:

import hashlib
print(hashlib.sha256(b'hello').hexdigest())

PHP:

echo hash('sha256', 'hello');

Common pitfalls

  • Using MD5 or SHA-1 for passwords or security-critical checks.
  • Hashing passwords without a per-user salt.
  • Confusing a checksum with authentication; a hash alone does not prove integrity against an active attacker.

Frequently asked questions

  • Is my input uploaded anywhere? No. Hashing can run locally in your browser using the Web Crypto API.
  • Can two inputs share a hash? In theory yes, a collision, but for SHA-256 finding one is computationally infeasible in practice.

Need a quick hash? Try the free Hash Generator — it computes MD5, SHA-1, SHA-256 and SHA-512 locally.