SHA-256 Hash Generator
Generate SHA-256 hashes for secure data verification and cryptographic applications. SHA-256 is part of the SHA-2 family and produces a 256-bit (64 character hexadecimal) hash. It's currently considered secure for all cryptographic purposes.
Understanding SHA-256
| Property | Value |
|---|---|
| Output length | 256 bits (32 bytes) |
| Hex representation | 64 characters |
| Security | Currently secure |
| Speed | Fast (slower than MD5) |
| Use case | Security, blockchain, certificates |
SHA-256 Implementation
``javascript
// Using Web Crypto API (browser)
async function sha256(text) {
const encoder = new TextEncoder();
const data = encoder.encode(text);
const hashBuffer = await crypto.subtle.digest('SHA-256', data);
const hashArray = Array.from(new Uint8Array(hashBuffer));
return hashArray.map(b => b.toString(16).padStart(2, '0')).join('');
}
// Node.js
const crypto = require('crypto');
function sha256Node(text) {
return crypto.createHash('sha256').update(text).digest('hex');
}
// Example
await sha256('hello world');
// "b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9"
`
SHA-256 Use Cases
| Use Case | Application |
|---|---|
| Password hashing | Combined with salt + iterations |
| File integrity | Verify downloads, backups |
| Digital signatures | Code signing, certificates |
| Blockchain | Bitcoin mining, transactions |
| API authentication | HMAC-SHA256 signatures |
| Data integrity | Database checksums |
SHA-256 vs Other Algorithms
| Algorithm | Output | Security | Speed |
|---|---|---|---|
| MD5 | 128-bit | Broken | Fastest |
| SHA-1 | 160-bit | Broken | Fast |
| SHA-256 | 256-bit | Secure | Fast |
| SHA-512 | 512-bit | Secure | Slower |
| SHA-3 | Variable | Secure | Moderate |
Password Hashing Note
While SHA-256 is secure, don't use it alone for passwords:
`javascript
// Bad: Plain SHA-256
sha256(password);
// Good: Use bcrypt or argon2
bcrypt.hash(password, 12);
`
Use SHA-256 for data integrity and cryptographic operations.
The Avalanche Effect
A one-character change produces a completely different digest — not a similar one. That
property is what makes a hash useful as a fingerprint:
| Input | MD5 | CRC32 |
|---|---|---|
hello | 5d41402abc4b2a76b9719d911017c592 | 3610a686 |
hello. | d94c10e437d18531e122ed0b45badd2a | 0a39d4f1 |
Hello | 8b1a9953c4611296a827abf8c47804d7 | f7d18982 |
hello and Hello differ by one bit of one byte, and share no part of their output.
RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is
d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.Digest Length and Collision Resistance
| Algorithm | Output | Birthday bound | Status |
|---|---|---|---|
| CRC32 | 32 bits | ~77,000 values | Checksum only |
| MD5 | 128 bits | 2⁶⁴ in theory | Broken — collisions in seconds |
| SHA-1 | 160 bits | 2⁸⁰ in theory | Broken — SHAttered, 2017 |
| RIPEMD-160 | 160 bits | 2⁸⁰ | No practical attack |
| SHA-256 | 256 bits | 2¹²⁸ | Current standard |
| SHA-512 | 512 bits | 2²⁵⁶ | Standard, faster on 64-bit |
Never Hash a Password With These
A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.