Hash Generator Algorithms Compared: What 128 to 512 Bits Actually Buy You

Five hash algorithms in one page, all updating as you type, and no guidance

on which row to copy. We ran all five algorithms on fixed inputs, read the

implementation behind each row, and compared the results. This is what the

sizes mean, which engine computes each digest, and where each algorithm

belongs.

Five algorithms, five fixed output sizes

The tool lists MD5 at 128 bits, SHA-1 at 160 bits, SHA-256 at 256 bits,

SHA-384 at 384 bits, and SHA-512 at 512 bits. Every digest renders as hex,

so each row has an exact character count you can verify at a glance: bits

divided by four.

MD5 128 bit 32 hex chars

SHA-1 160 bit 40 hex chars

SHA-256 256 bit 64 hex chars

SHA-384 384 bit 96 hex chars

SHA-512 512 bit 128 hex chars

We hashed the word hello with all five. The MD5 row is 32 characters, the

SHA-384 row is 96, and the SHA-512 row is 128. If any row you copy has a

different length, the input changed between your two runs or you copied a

partial digest.

Two engines compute your hashes

The rows come from two different code paths, and the difference matters.

MD5 is implemented in roughly 120 lines of JavaScript inside the component,

with no library dependency. The block starts from the four RFC 1321 state

constants 1732584193, -271733879, -1732584194, and 271733878, converts input

to UTF-8 bytes, and runs the four rounds. We ran this exact function against

Node crypto on three inputs, including the Turkish text ığdır that exercises

the multi-byte path. Every digest matched.

The SHA family goes through the Web Crypto API. The tool encodes your text

to UTF-8 bytes with TextEncoder and calls crypto.subtle.digest for SHA-1,

SHA-256, SHA-384, and SHA-512 in parallel. Each byte of output becomes two

hex digits, so leading zeros survive.

The engine split has one consequence you should know. Browsers expose

crypto.subtle only in secure contexts. On a plain HTTP origin the four SHA

rows stay empty while MD5 still works, because MD5 needs no platform API.

Four empty rows on an insecure origin are a browser policy, not a broken

input.

Behavior you can rely on

Hashing is deterministic. The same bytes produce the same digest on every

run, every machine, every year. The tool hashes your text 150 ms after you

stop typing, so fast typing does not fire a digest per keystroke.

The case toggle switches the hex output between lowercase and uppercase.

It changes the display, never the digest. If a downstream system documents

lowercase hex, paste the lowercase form rather than trusting the toggle

state from your last visit.

Which algorithm for which job

1. Checksums against accidental corruption, such as verifying a copy or a

download against a published value: SHA-256 or better. Accidents do not

forge digests, but SHA-256 costs you nothing over the weaker options.

2. Integrity against an attacker who can choose inputs: SHA-256 minimum,

SHA-512 if you want more margin. Never MD5, never SHA-1. Collision

attacks against both are public and practical. The SHAttered

demonstration in 2017 produced two different PDF files with one identical

SHA-1 digest, and certificate authorities dropped SHA-1 the same year.

3. Password storage: none of these five. Fast hashes help whoever attacks a

stolen database. Use Argon2 or bcrypt, which are slow by design. The

expert note in our own tool page states the same rule.

4. Legacy deduplication of non-hostile data where an old system demands MD5:

acceptable. The data is not under attack, and compatibility wins.

Verified digests you can reproduce

Run these inputs through any correct implementation and compare:

input: hello

MD5 5d41402abc4b2a76b9719d911017c592

SHA-1 aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d

SHA-256 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824

SHA-384 59e1748777448c69de6b800d7a33bbfb9ff1b463e44354c3553bcdb9c666fa9

0125a3c79f90397bdf5f6a13de828684f

SHA-512 9b71d224bd62f3785d96d46ad3ea3d73319bfbc2890caadae2dff72519673ca7

2323c3d99ba5c11d7c7acc6e14b8c5da0c4663475c2e5c3adef46f73bcdec043

input: The quick brown fox jumps over the lazy dog

MD5 9e107d9d372bb6826bd81d3542a419d6

SHA-1 2fd4e1c67a2d28fced849ee1bb76e7391b93eb12

SHA-256 d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592

The two long rows wrap across two lines here. The tool renders each on one

line with a copy button, which is the safer way to move a 128-character

digest.

Honest downsides

The tool hashes text, not files. A document digest requires a tool that

reads bytes. SHA-1 and MD5 are collision-broken for security purposes even

though they remain correct for identifying non-hostile inputs. And a hash

cannot be reversed, so this page never tells you what input produced a

digest you already have. Any site promising that is guessing a dictionary.

Checklist before you copy a digest

  • Match the algorithm name between the tool and the expected value.
  • Match the case, lowercase or uppercase, to the documented format.
  • Match the character count to the table above.
  • Re-run after any input edit, including invisible trailing whitespace.
  • For passwords, use Argon2 or bcrypt instead.

If you maintain a compatibility table of digests from another stack, run the

two inputs above against your system and compare. Generate all five rows for

your own inputs in the hash generator at

https://webrecast.com/en/hash-generator