What is a hash function?
A hash function turns any content — a sentence, a piece of software, a multi-gigabyte backup — into a fixed-length string called a digest or hash. Three properties define it: the output is always the same size whatever the input, the same content always produces the same digest, and going from the digest back to the input must be impractical. It is this third point that separates a cryptographic hash from a checksum like CRC32.
In practice, two uses cover most of the ground. Verifying integrity : the publisher posts the digest of their file, you recompute it, and a match proves the download was not tampered with. Comparing contents : instead of keeping the documents themselves, you keep their digests — identical digests mean identical contents, without revealing anything about their nature.
Which algorithm should you choose today?
SHA-256 is the default answer: standardised by the NSA, then adopted everywhere, implemented in every language, and with no known collision. SHA-512 fits large volumes when the processor is 64-bit, often faster than its cousin on that kind of architecture. SHA-384 brings nothing special beyond a longer variant. For keyed message signing, the HMAC-SHA-256 is the reference: it combines the secret key and the hash, so only the key holder can produce the same value.
The MD5 and the SHA-1 remain useful for non-sensitive checks — an index, a cache, duplicate detection — where speed matters more than resistance. The CRC32, for its part, is not a cryptographic hash: it detects accidental corruption, but a deliberate alteration can be crafted in seconds.
Why are MD5 and SHA-1 considered broken?
Because researchers have produced, for each of them, two different documents sharing the same digest. For MD5, the demonstration dates back to 2004; for SHA-1, a real collision was produced in 2017 under the name SHAttered. A single collision is enough to break a signature: if the attacker chooses the document and the publisher only hashes it, they can obtain a signature over entirely different content. That is why TLS certificates, software updates and package signatures have dropped these algorithms.
What hashing does not do
Hashing is not encrypting: a digest is irreversible by design, but it does not protect the content by making it unreadable. Hashing encrypts nothing, replaces neither TLS nor an encryption key, and does not protect a password on its own — that is a job for bcrypt, scrypt or Argon2, designed to be slow. Finally, hashing twice strengthens nothing: chaining algorithms only adds a fragile layer where a single unbroken function would suffice.
Recommended for
System administrators and CIOs who verify distribution checksums, developers who seal artifacts or authenticate webhooks, auditors and compliance staff who check backup integrity, journalists and analysts who compare documents without distributing them, cryptography students working with the notions of digest, collision and salt — and anyone who wants to hash some content quickly and without a trace, complemented by the password generator, theBase64 encoder decoder, the JWT decoder, the regex tester and the character counter.