Five hash algorithms in one page, all updating as you type, and no guidance
on which row to copy. We ran all five algorithms on fixed inputs, read the
implementation behind each row, and compared the results. This is what the
sizes mean, which engine computes each digest, and where each algorithm
belongs.
Five algorithms, five fixed output sizes
The tool lists MD5 at 128 bits, SHA-1 at 160 bits, SHA-256 at 256 bits,
SHA-384 at 384 bits, and SHA-512 at 512 bits. Every digest renders as hex,
so each row has an exact character count you can verify at a glance: bits
divided by four.
MD5 128 bit 32 hex chars
SHA-1 160 bit 40 hex chars
SHA-256 256 bit 64 hex chars
SHA-384 384 bit 96 hex chars
SHA-512 512 bit 128 hex chars
We hashed the word hello with all five. The MD5 row is 32 characters, the
SHA-384 row is 96, and the SHA-512 row is 128. If any row you copy has a
different length, the input changed between your two runs or you copied a
partial digest.
Two engines compute your hashes
The rows come from two different code paths, and the difference matters.
MD5 is implemented in roughly 120 lines of JavaScript inside the component,
with no library dependency. The block starts from the four RFC 1321 state
constants 1732584193, -271733879, -1732584194, and 271733878, converts input
to UTF-8 bytes, and runs the four rounds. We ran this exact function against
Node crypto on three inputs, including the Turkish text ığdır that exercises
the multi-byte path. Every digest matched.
The SHA family goes through the Web Crypto API. The tool encodes your text
to UTF-8 bytes with TextEncoder and calls crypto.subtle.digest for SHA-1,
SHA-256, SHA-384, and SHA-512 in parallel. Each byte of output becomes two
hex digits, so leading zeros survive.
The engine split has one consequence you should know. Browsers expose
crypto.subtle only in secure contexts. On a plain HTTP origin the four SHA
rows stay empty while MD5 still works, because MD5 needs no platform API.
Four empty rows on an insecure origin are a browser policy, not a broken
input.
Behavior you can rely on
Hashing is deterministic. The same bytes produce the same digest on every
run, every machine, every year. The tool hashes your text 150 ms after you
stop typing, so fast typing does not fire a digest per keystroke.
The case toggle switches the hex output between lowercase and uppercase.
It changes the display, never the digest. If a downstream system documents
lowercase hex, paste the lowercase form rather than trusting the toggle
state from your last visit.
Which algorithm for which job
1. Checksums against accidental corruption, such as verifying a copy or a
download against a published value: SHA-256 or better. Accidents do not
forge digests, but SHA-256 costs you nothing over the weaker options.
2. Integrity against an attacker who can choose inputs: SHA-256 minimum,
SHA-512 if you want more margin. Never MD5, never SHA-1. Collision
attacks against both are public and practical. The SHAttered
demonstration in 2017 produced two different PDF files with one identical
SHA-1 digest, and certificate authorities dropped SHA-1 the same year.
3. Password storage: none of these five. Fast hashes help whoever attacks a
stolen database. Use Argon2 or bcrypt, which are slow by design. The
expert note in our own tool page states the same rule.
4. Legacy deduplication of non-hostile data where an old system demands MD5:
acceptable. The data is not under attack, and compatibility wins.
Verified digests you can reproduce
Run these inputs through any correct implementation and compare:
input: hello
MD5 5d41402abc4b2a76b9719d911017c592
SHA-1 aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d
SHA-256 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
SHA-384 59e1748777448c69de6b800d7a33bbfb9ff1b463e44354c3553bcdb9c666fa9
0125a3c79f90397bdf5f6a13de828684f
SHA-512 9b71d224bd62f3785d96d46ad3ea3d73319bfbc2890caadae2dff72519673ca7
2323c3d99ba5c11d7c7acc6e14b8c5da0c4663475c2e5c3adef46f73bcdec043
input: The quick brown fox jumps over the lazy dog
MD5 9e107d9d372bb6826bd81d3542a419d6
SHA-1 2fd4e1c67a2d28fced849ee1bb76e7391b93eb12
SHA-256 d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592
The two long rows wrap across two lines here. The tool renders each on one
line with a copy button, which is the safer way to move a 128-character
digest.
Honest downsides
The tool hashes text, not files. A document digest requires a tool that
reads bytes. SHA-1 and MD5 are collision-broken for security purposes even
though they remain correct for identifying non-hostile inputs. And a hash
cannot be reversed, so this page never tells you what input produced a
digest you already have. Any site promising that is guessing a dictionary.
Checklist before you copy a digest
- Match the algorithm name between the tool and the expected value.
- Match the case, lowercase or uppercase, to the documented format.
- Match the character count to the table above.
- Re-run after any input edit, including invisible trailing whitespace.
- For passwords, use Argon2 or bcrypt instead.
If you maintain a compatibility table of digests from another stack, run the
two inputs above against your system and compare. Generate all five rows for
your own inputs in the hash generator at
https://webrecast.com/en/hash-generator