Explanation
How Hash Generator works
The hash generator calculates cryptographic checksums for arbitrary texts directly in the browser. The entered text is encoded as UTF-8 and processed by the selected SHA algorithm.
SHA-256 is the most common algorithm and produces a 256-bit hash (64 hex characters). SHA-384 produces 96 hex characters, SHA-512 produces 128 hex characters. These algorithms belong to the SHA-2 family, standardised by NIST in FIPS 180-4.
Hex and standard Base64 represent the same digest bytes. Base64 is more compact but may contain +, / and padding and is not automatically URL-safe.
Common mistakes
- Confusing hashing with encryption: A hash is not a reversible plaintext representation. Encryption serves a different purpose and is reversible with the right key.
- Using MD5 or SHA-1 for security purposes: Both algorithms have known collision attacks and are considered insecure according to BSI TR-02102-1.
- Using SHA hashes for password storage: Simple SHA hashes can be computed too fast. Use bcrypt, scrypt or Argon2 with a salt and work factor.
- Interpreting hash equality as identity: Equal hashes mean equal input with extremely high probability, but not with absolute certainty (theoretical possibility of collision).
Limits of this tool
- No salting function — unsuitable for password storage.
- Text input only, no files (use dedicated tools for file hashes).
- No HMAC mode (keyed hashing) — only simple hash calculation.
- No verification against known hash values integrated.
- Whitespace, line breaks and Unicode normalization are not unified but hashed as part of the UTF-8 input.
Sources
- BSI TR-02102-1: Cryptographic mechanisms — recommendations and key lengths. German Federal Office for Information Security.
- NIST FIPS 180-4: Secure Hash Standard (SHS). Defines SHA-256, SHA-384, SHA-512.
- RFC 1321: MD5 Message-Digest Algorithm (historical, not recommended for security).
- Web Crypto API: W3C standard for cryptographic operations in the browser (crypto.subtle.digest).