MD5, SHA-1, and SHA-256 all turn input into a fixed-length digest, but they do not provide the same collision resistance. MD5 and SHA-1 should not be selected for new security designs. SHA-256 remains the practical baseline among these three for modern interoperable applications.
Quick comparison
| Algorithm | Digest | Modern guidance |
|---|---|---|
| MD5 | 128 bits / 32 hex characters | Broken for collision-resistant security uses |
| SHA-1 | 160 bits / 40 hex characters | Retired for security uses; migrate away |
| SHA-256 | 256 bits / 64 hex characters | Current minimum encouraged by NIST for interoperable hash applications |
What a cryptographic hash does
A hash function accepts input of any length and produces a fixed-length digest. The same bytes produce the same digest. A tiny input change should produce a very different result. Secure designs also need it to be infeasible to recover the input from the digest or to create two different inputs with the same digest.
Hashing is one-way; encryption is reversible with a key. Neither a bare hash nor a checksum proves who created a file.
Why MD5 is no longer suitable for signatures
Published collision attacks mean MD5 is not prudent when collision resistance is required. An attacker can exploit a collision when the security design assumes two different files cannot share a digest. Do not choose MD5 for certificates, signatures, tamper-resistant manifests, or new authentication protocols.
You may still encounter MD5 as a non-adversarial download error check in old systems. Label that limited purpose clearly and prefer a stronger published checksum when available.
Why SHA-1 should be retired
SHA-1 also has practical collision weaknesses. NIST has retired SHA-1 for protecting information and is transitioning remaining uses. Existing integrations may expose SHA-1 for compatibility, but new systems should not treat it as a modern security choice.
When SHA-256 is the right choice
SHA-256 belongs to the SHA-2 family and produces a 256-bit digest. It is widely used for file-integrity checks, content addressing, digital-signature workflows, and keyed constructions such as HMAC-SHA-256. Use the exact algorithm and encoding required by the protocol; a SHA-256 hex string and Base64-encoded digest represent the same bytes differently.
Do not use a fast general hash for passwords
Password storage needs a dedicated, salted, deliberately expensive password-hashing function such as Argon2id, scrypt, bcrypt, or PBKDF2 according to the platform's current security guidance. Fast hashes make large guessing attacks cheaper. Simply applying SHA-256 repeatedly without a reviewed password-hashing design is not a substitute.
Compare a downloaded file safely
- Obtain the expected SHA-256 digest through a trusted channel.
- Open the Hash Generator and select the downloaded file.
- Calculate SHA-256 locally.
- Compare every character, not just the beginning.
- If the values differ, stop and obtain a clean copy.
A matching digest confirms byte-for-byte equality with the referenced digest, but trust still depends on where that expected value came from.
Frequently asked questions
Is SHA-256 encryption?
No. SHA-256 is a one-way hash function and has no decryption key. Encryption is designed to recover plaintext with an authorized key; hashing is used to derive a fixed-length digest.
Can I use MD5 only to detect an accidental download error?
Legacy systems still do this, and RFC 6151 distinguishes non-security error checking from collision-resistant uses. Prefer a publisher-provided SHA-256 checksum when available and never describe MD5 as proof against deliberate tampering.
Is SHA-512 automatically better than SHA-256?
A longer digest is not automatically the best protocol choice. Use the algorithm required by the standard or threat model. Among the three compared here, SHA-256 is the current practical baseline for new interoperable hash uses.
Sources checked
MD5, SHA-1, and SHA-256 security guidance was compared on August 12, 2026; confirm current NIST policy before selecting a hash for integrity or authentication.