MD5, SHA-1 and SHA-256 — Which Hash Should You Use?
hashsecuritysha256
A hash function turns any input into a fixed-size string of characters. The same input always produces the same hash, and even a tiny change to the input produces a completely different result. Hashes are used for checksums, password storage, and data integrity.
The common algorithms
- MD5 produces a 128-bit hash. It is fast but cryptographically broken and should not be used for security.
- SHA-1 produces a 160-bit hash. It is also considered weak and is being phased out.
- SHA-256 produces a 256-bit hash and is the safe default for most modern use cases.
- SHA-512 is a larger variant of the SHA-2 family and is useful when more output bits are wanted.
Hashing is not encryption
Encryption can be reversed with a key, while a good hash is one-way. That is why passwords should be stored as salted hashes rather than encrypted text.
Generating hashes in code
JavaScript:
const data = new TextEncoder().encode('hello')
const digest = await crypto.subtle.digest('SHA-256', data)
console.log([...new Uint8Array(digest)].map(b => b.toString(16).padStart(2, '0')).join(''))
Python:
import hashlib
print(hashlib.sha256(b'hello').hexdigest())
PHP:
echo hash('sha256', 'hello');
Common pitfalls
- Using MD5 or SHA-1 for passwords or security-critical checks.
- Hashing passwords without a per-user salt.
- Confusing a checksum with authentication; a hash alone does not prove integrity against an active attacker.
Frequently asked questions
- Is my input uploaded anywhere? No. Hashing can run locally in your browser using the Web Crypto API.
- Can two inputs share a hash? In theory yes, a collision, but for SHA-256 finding one is computationally infeasible in practice.
Need a quick hash? Try the free Hash Generator — it computes MD5, SHA-1, SHA-256 and SHA-512 locally.