SHA-1 Hash Generator
Generate SHA-1 hashes for data verification and legacy compatibility. SHA-1 produces a 160-bit (40 character hexadecimal) hash. While deprecated for security use, SHA-1 is still used in Git and some legacy systems.
Understanding SHA-1
| Property | Value |
|---|---|
| Output length | 160 bits (20 bytes) |
| Hex representation | 40 characters |
| Security | Deprecated (collisions found) |
| Speed | Fast |
| Use case | Git commits, legacy systems |
SHA-1 Implementation
``javascript
// Using Web Crypto API
async function sha1(text) {
const encoder = new TextEncoder();
const data = encoder.encode(text);
const hashBuffer = await crypto.subtle.digest('SHA-1', data);
const hashArray = Array.from(new Uint8Array(hashBuffer));
return hashArray.map(b => b.toString(16).padStart(2, '0')).join('');
}
// Node.js
const crypto = require('crypto');
function sha1Node(text) {
return crypto.createHash('sha1').update(text).digest('hex');
}
// Example
await sha1('hello world');
// "2aae6c35c94fcfb415dbe95f408b9ce91ee846ed"
`
Git and SHA-1
Git uses SHA-1 for commit identifiers:
`bash
# View commit hash
git log --oneline
# a1b2c3d (HEAD -> main) Latest commit
# SHA-1 is used for:
# - Commit IDs
# - Tree objects
# - Blob objects
# - Tag objects
`
SHA-1 Security Status
| Year | Event |
|---|---|
| 2005 | Theoretical weaknesses found |
| 2017 | First practical collision (SHAttered) |
| 2019 | Chosen-prefix collision |
| 2020 | Attack cost reduced to ~$45k |
Migration from SHA-1
| Use | Migrate To |
|---|---|
| Certificates | SHA-256 (required since 2017) |
| Code signing | SHA-256 |
| Data integrity | SHA-256 |
| Git | SHA-256 (Git 2.29+) |
Use SHA-1 only for Git compatibility or legacy system integration.The Avalanche Effect
A one-character change produces a completely different digest — not a similar one. That
property is what makes a hash useful as a fingerprint:
| Input | MD5 | CRC32 |
|---|---|---|
hello | 5d41402abc4b2a76b9719d911017c592 | 3610a686 |
hello. | d94c10e437d18531e122ed0b45badd2a | 0a39d4f1 |
Hello | 8b1a9953c4611296a827abf8c47804d7 | f7d18982 |
hello and Hello differ by one bit of one byte, and share no part of their output.
RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is
d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.Digest Length and Collision Resistance
| Algorithm | Output | Birthday bound | Status |
|---|---|---|---|
| CRC32 | 32 bits | ~77,000 values | Checksum only |
| MD5 | 128 bits | 2⁶⁴ in theory | Broken — collisions in seconds |
| SHA-1 | 160 bits | 2⁸⁰ in theory | Broken — SHAttered, 2017 |
| RIPEMD-160 | 160 bits | 2⁸⁰ | No practical attack |
| SHA-256 | 256 bits | 2¹²⁸ | Current standard |
| SHA-512 | 512 bits | 2²⁵⁶ | Standard, faster on 64-bit |
Never Hash a Password With These
A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.