Security

SHA-256 Hashing Explained

A hash is a fixed-length fingerprint of data. SHA-256 underpins signatures, integrity checks and blockchains — and it is not encryption.

Updated 16 September 2026 · 7 min read
Advertisement

What a hash is

A cryptographic hash takes any input and produces a fixed-length output — the digest. SHA-256 always returns 256 bits, shown as 64 hexadecimal characters:

SHA-256("hello") =
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824

Change one character of the input and the output changes completely — the avalanche effect. Compute hashes with the free SHA-256 generator.

Properties of a good hash

  • Deterministic — same input, same output.
  • One-way — you cannot reverse it.
  • Collision-resistant — infeasible to find two inputs with the same hash.
  • Fast to compute.

What hashing is used for

  • Integrity — verify a download or file was not altered.
  • Digital signatures — sign the hash, not the whole file.
  • Password storage — with a salt and a slow algorithm.
  • Blockchains — chaining blocks by hash.
  • Content addressing — Git commits, deduplication.

Hashing is not encryption

Encryption is reversible with a key; hashing is irreversible. You cannot "decrypt" a hash — you can only hash a candidate and compare. Confusing the two leads to broken security models.

MD5, SHA-1, SHA-256, SHA-512

  • MD5 / SHA-1 — broken for security (collisions found). Fine only for non-security checksums.
  • SHA-256 / SHA-512 — part of the SHA-2 family, still considered secure.
  • SHA-3 — a newer, different design.

Salted, slow hashing for passwords

For passwords, always use bcrypt, scrypt or Argon2: they are deliberately slow and salted, which makes brute-force attacks far harder. A fast hash like SHA-256 lets attackers try billions of guesses per second.

Verify integrity

To check a file matches its published checksum, hash it locally and compare. Everything stays in your browser with the SHA-256 tool — your data is never uploaded.

Advertisement
Help Center

SHA-256 Hashing Explained — FAQ

A cryptographic hash function that turns any input into a fixed 256-bit (64 hexadecimal character) digest. The same input always produces the same hash.

No. Hashing is one-way by design. You cannot recover the input from the hash; you can only compare hashes.

Not directly. Password storage should use a slow, salted algorithm such as bcrypt, scrypt or Argon2, not a fast hash like SHA-256.

Keep reading
Advertisement