Last updated 3 September 2026
What a hash is for
A hash turns any input into a fixed-length string that changes completely if even one character of the input changes. It's one-directional — there's no way to run it backwards — which is what makes it useful for checking that a file wasn't altered, verifying a download matches what the publisher intended, or confirming two pieces of text are identical without comparing them directly.
Choosing an algorithm
SHA-256 is the sensible default for almost everything — it's what Git commit hashes and most modern checksums use. SHA-1 is older and weaker, kept mainly for compatibility with systems that still expect it. SHA-384 and SHA-512 produce longer hashes for cases that specifically call for it. MD5 isn't offered at all — it's not part of the browser's built-in crypto API, and it's been considered broken for security use for years.
Hashing is not encryption
Encryption is reversible with a key; hashing is not reversible at all. A hash function takes any input and produces a fixed-length fingerprint, and there is no operation that turns that fingerprint back into the original. Change a single character of the input and the output changes completely — an avalanche effect that is what makes hashes useful for detecting any modification, however small.
That property drives the two main uses. Integrity checking: a project publishes the SHA-256 of a download, you hash your copy, and matching values mean the file arrived intact. Deduplication and comparison: two files with the same hash are almost certainly identical, which is far cheaper than comparing them byte by byte.
Which algorithm, and one important exception
MD5 and SHA-1 are both broken for security purposes. Researchers have demonstrated practical collisions — two different inputs producing the same hash — which means neither can prove a file has not been tampered with. They are still fine as fast checksums against accidental corruption, but not against a deliberate attacker. SHA-256 is the current sensible default.
The exception concerns passwords, and it matters. A general-purpose hash is designed to be fast, which is exactly wrong for storing passwords, because an attacker with a leaked database can try billions of guesses per second. Passwords need a deliberately slow, salted algorithm built for the job — bcrypt, scrypt or Argon2. Storing a plain SHA-256 of a password, salted or not, is a known and serious weakness rather than a reasonable shortcut.
Common questions
Why isn't MD5 an option?
Browsers don't include MD5 in their built-in cryptographic API — only the SHA family. MD5 is also considered broken for security purposes, since collisions can be deliberately constructed, so SHA-256 or better is the modern default anyway.
Which algorithm should I use?
SHA-256 is the standard general-purpose choice — it's what Git, TLS certificates and most modern checksums use. SHA-1 is weaker and mainly relevant for compatibility with older systems; SHA-384 and SHA-512 are used where a longer hash is specifically required.
Can a hash be reversed back to the original text?
No, not by design. A hash function only goes one way. The only way to "find" matching input is to guess many inputs and hash each one, which is why hashing weak, predictable text like common passwords is not actually secure.
Can a hash be reversed?
No. Hashing is one-way by design, unlike encryption which is reversible with a key. What attackers do instead is guess inputs and compare the resulting hashes, which is why common passwords are recovered quickly and long random strings are not.
Is MD5 still safe to use?
Not for security. Practical collisions have been demonstrated for both MD5 and SHA-1, meaning two different files can be made to share a hash, so neither proves a file is untampered. They remain acceptable as fast checksums against accidental corruption. Use SHA-256 otherwise.
Should I hash passwords with SHA-256?
No. General-purpose hashes are built to be fast, which lets an attacker test billions of guesses per second against a leaked database. Passwords need a deliberately slow, salted algorithm such as bcrypt, scrypt or Argon2.