File Checksum Calculator
Calculate file checksums to verify file integrity and detect corruption or tampering. Support for MD5, SHA-1, SHA-256, and SHA-512 hashes for comprehensive file verification.
Understanding File Checksums
| Purpose | How It Works |
|---|---|
| Integrity verification | Same file = same hash |
| Download verification | Compare hash to source |
| Duplicate detection | Identical files = identical hash |
| Tampering detection | Any change = different hash |
Common Checksum Algorithms
| Algorithm | Length | Speed | Use Case |
|---|---|---|---|
| MD5 | 32 chars | Fastest | Legacy, quick checks |
| SHA-1 | 40 chars | Fast | Git, legacy |
| SHA-256 | 64 chars | Fast | Recommended |
| SHA-512 | 128 chars | Moderate | Maximum security |
Calculate Checksums (Command Line)
``bash
# Linux/Mac
md5sum filename.zip
sha1sum filename.zip
sha256sum filename.zip
sha512sum filename.zip
# Mac alternative
shasum -a 256 filename.zip
# Windows
certutil -hashfile filename.zip MD5
certutil -hashfile filename.zip SHA256
`
Calculate Checksums (JavaScript)
`javascript
// Browser: File input to hash
async function calculateFileHash(file, algorithm = 'SHA-256') {
const arrayBuffer = await file.arrayBuffer();
const hashBuffer = await crypto.subtle.digest(algorithm, arrayBuffer);
const hashArray = Array.from(new Uint8Array(hashBuffer));
return hashArray.map(b => b.toString(16).padStart(2, '0')).join('');
}
// Usage with file input
document.querySelector('input[type="file"]')
.addEventListener('change', async (e) => {
const file = e.target.files[0];
const hash = await calculateFileHash(file);
console.log(SHA-256: ${hash});
});
// Node.js
const crypto = require('crypto');
const fs = require('fs');
function calculateFileHashNode(filePath, algorithm = 'sha256') {
return new Promise((resolve, reject) => {
const hash = crypto.createHash(algorithm);
const stream = fs.createReadStream(filePath);
stream.on('data', data => hash.update(data));
stream.on('end', () => resolve(hash.digest('hex')));
stream.on('error', reject);
});
}
`
Verifying Downloads
1. Download the file
2. Get the official checksum from the source
3. Calculate your file's checksum
4. Compare them (must match exactly)
`bash
# Verify against expected hash
echo "expected_hash_here filename.zip" | sha256sum -c
`
When Checksums Don't Match
| Possible Cause | Solution |
|---|---|
| Incomplete download | Re-download |
| Corrupted file | Re-download |
| Wrong file version | Check version |
| Malicious tampering | Don't use file |
| Wrong algorithm | Verify algorithm used |
The Avalanche Effect
A one-character change produces a completely different digest — not a similar one. That
property is what makes a hash useful as a fingerprint:
| Input | MD5 | CRC32 |
|---|---|---|
hello | 5d41402abc4b2a76b9719d911017c592 | 3610a686 |
hello. | d94c10e437d18531e122ed0b45badd2a | 0a39d4f1 |
Hello | 8b1a9953c4611296a827abf8c47804d7 | f7d18982 |
hello and Hello differ by one bit of one byte, and share no part of their output.
RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is
d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.Digest Length and Collision Resistance
| Algorithm | Output | Birthday bound | Status |
|---|---|---|---|
| CRC32 | 32 bits | ~77,000 values | Checksum only |
| MD5 | 128 bits | 2⁶⁴ in theory | Broken — collisions in seconds |
| SHA-1 | 160 bits | 2⁸⁰ in theory | Broken — SHAttered, 2017 |
| RIPEMD-160 | 160 bits | 2⁸⁰ | No practical attack |
| SHA-256 | 256 bits | 2¹²⁸ | Current standard |
| SHA-512 | 512 bits | 2²⁵⁶ | Standard, faster on 64-bit |
Never Hash a Password With These
A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.