Cryptographic Hash Functions Explained
A cryptographic hash function takes an input of any length and produces a fixed-length output called a digest or hash. The same input always produces the same output. Crucially, hash functions are one-way: given only the hash, recovering the original input is computationally infeasible. This property makes them essential for data integrity verification, password storage, and digital signatures.
Algorithm Reference
SHA-256 — The Current Standard
Part of the SHA-2 family, designed by the NSA and standardised by NIST in 2001. Produces a 256-bit (64-character hex) digest. SHA-256 is used in Bitcoin proof-of-work, TLS certificate integrity, and most modern authentication systems. It has no known practical attack and remains the recommended algorithm for new security-sensitive applications.
SHA-1 — Legacy Support Only
Produces a 160-bit (40-character hex) digest. SHA-1 was the dominant hash function from 1995 through the early 2010s but was cryptographically broken in 2017 (Google's SHAttered attack demonstrated a practical collision). Do not use SHA-1 for new security applications. Its remaining valid uses are non-security checksums and legacy Git commit identification.
MD5 — Checksum Use Only
Produces a 128-bit (32-character hex) digest. MD5 collisions can be generated in seconds on modern hardware. Never use MD5 for passwords, authentication, or any security purpose. Its only remaining legitimate uses are non-cryptographic checksums (verifying a file was not corrupted in transit) and legacy database deduplication.
Security Hierarchy
For any new application, always choose SHA-256. SHA-1 and MD5 are provided for legacy compatibility and verification tasks only.