Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

SHA-1 Hash Generator

Generate SHA-1 hashes

SHA-1 digest
—
MD5
—
SHA-256
—
SHA-384
—
SHA-512
—
CRC32
—
RIPEMD-160
—

SHA-1 is broken for collision resistance. It is fine for checksums and cache keys, but never use it for signatures, certificates or password storage.

SHA-1 Hash Generator

Generate SHA-1 hashes for data verification and legacy compatibility. SHA-1 produces a 160-bit (40 character hexadecimal) hash. While deprecated for security use, SHA-1 is still used in Git and some legacy systems.

Understanding SHA-1

PropertyValue
Output length160 bits (20 bytes)
Hex representation40 characters
SecurityDeprecated (collisions found)
SpeedFast
Use caseGit commits, legacy systems

SHA-1 Implementation

``javascript // Using Web Crypto API async function sha1(text) { const encoder = new TextEncoder(); const data = encoder.encode(text); const hashBuffer = await crypto.subtle.digest('SHA-1', data); const hashArray = Array.from(new Uint8Array(hashBuffer)); return hashArray.map(b => b.toString(16).padStart(2, '0')).join(''); }

// Node.js const crypto = require('crypto');

function sha1Node(text) { return crypto.createHash('sha1').update(text).digest('hex'); }

// Example await sha1('hello world'); // "2aae6c35c94fcfb415dbe95f408b9ce91ee846ed" `

Git and SHA-1

Git uses SHA-1 for commit identifiers:

`bash # View commit hash git log --oneline # a1b2c3d (HEAD -> main) Latest commit

# SHA-1 is used for: # - Commit IDs # - Tree objects # - Blob objects # - Tag objects `

SHA-1 Security Status

YearEvent
2005Theoretical weaknesses found
2017First practical collision (SHAttered)
2019Chosen-prefix collision
2020Attack cost reduced to ~$45k

Migration from SHA-1

UseMigrate To
CertificatesSHA-256 (required since 2017)
Code signingSHA-256
Data integritySHA-256
GitSHA-256 (Git 2.29+)
Use SHA-1 only for Git compatibility or legacy system integration.

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

Is SHA-1 still safe to use?

SHA-1 is not safe for security purposes. Practical collision attacks exist (SHAttered attack, 2017). Don't use SHA-1 for digital signatures, certificates, or any security-critical application. It's acceptable for non-security uses like Git commit IDs (where collision risk is low) or legacy system compatibility.

Why does Git still use SHA-1?

Git uses SHA-1 for object identification, not security. Creating a malicious collision that also forms a valid Git object is extremely difficult. Git is migrating to SHA-256 (available in Git 2.29+). For existing repositories, SHA-1 remains safe because attackers would need to create collisions that are also valid Git objects, which is much harder than a basic collision.

How long is a SHA-1 hash?

SHA-1 produces a 160-bit hash, displayed as 40 hexadecimal characters. Git often shows abbreviated versions (7-10 characters) but stores the full hash. Example: "2aae6c35c94fcfb415dbe95f408b9ce91ee846ed".

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need