SHA-256 Hashing Explained
A hash is a fixed-length fingerprint of data. SHA-256 underpins signatures, integrity checks and blockchains — and it is not encryption.
What a hash is
A cryptographic hash takes any input and produces a fixed-length output — the digest. SHA-256 always returns 256 bits, shown as 64 hexadecimal characters:
SHA-256("hello") =
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
Change one character of the input and the output changes completely — the avalanche effect. Compute hashes with the free SHA-256 generator.
Properties of a good hash
- Deterministic — same input, same output.
- One-way — you cannot reverse it.
- Collision-resistant — infeasible to find two inputs with the same hash.
- Fast to compute.
What hashing is used for
- Integrity — verify a download or file was not altered.
- Digital signatures — sign the hash, not the whole file.
- Password storage — with a salt and a slow algorithm.
- Blockchains — chaining blocks by hash.
- Content addressing — Git commits, deduplication.
Hashing is not encryption
Encryption is reversible with a key; hashing is irreversible. You cannot "decrypt" a hash — you can only hash a candidate and compare. Confusing the two leads to broken security models.
MD5, SHA-1, SHA-256, SHA-512
- MD5 / SHA-1 — broken for security (collisions found). Fine only for non-security checksums.
- SHA-256 / SHA-512 — part of the SHA-2 family, still considered secure.
- SHA-3 — a newer, different design.
Salted, slow hashing for passwords
For passwords, always use bcrypt, scrypt or Argon2: they are deliberately slow and salted, which makes brute-force attacks far harder. A fast hash like SHA-256 lets attackers try billions of guesses per second.
Verify integrity
To check a file matches its published checksum, hash it locally and compare. Everything stays in your browser with the SHA-256 tool — your data is never uploaded.