Hash Generator
Generate SHA-256, SHA-1, and MD5 hashes in your browser. No data leaves your device.
π How to Use
Type the text you want to hash. All hash values update in real time as you type.
SHA-256 (recommended), SHA-1, and MD5 hashes are displayed simultaneously.
Click the π Copy button for any hash algorithm to save it to your clipboard. SHA-256 is the most secure.
About the Hash Generator
A cryptographic hash function takes an input of any size — a byte, a text file, a multi-gigabyte image — and returns a small, fixed-length fingerprint called a digest. The same input always yields the same digest, and any change, even one flipped bit, yields a completely different digest. This tool computes MD5, SHA-1, and SHA-256 in your browser through the Web Crypto SubtleCrypto API; the input never leaves your device.
How it works
Each algorithm returns a digest of a fixed bit length: MD5 is 128-bit (32 hex characters), SHA-1 is 160-bit (40 hex characters), and SHA-256 is 256-bit (64 hex characters). The digest is shown as hexadecimal because each byte maps to two 0–9/a–f characters. Most of these algorithms use the Merkle–Damgård construction: the input is padded to a multiple of a 512-bit block, a length suffix is appended, and the message is processed one block at a time through a compression function that folds each block into a running state. The final state is the digest.
The defining property is collision resistance: finding two distinct inputs that hash to the same digest must be infeasible. MD5 and SHA-1 are broken — practical collision attacks exist — so they must not protect anything of value. SHA-256 has no known practical collision attack and is the current default. Hashing is one-way: there is no decryption. You can compute a digest from data, but not recover data from a digest, which makes hashes fit for integrity checks and content addressing.
Common use cases
- Verifying file integrity — compare a download's digest to a published checksum
- Detecting changes in config, logs, or backups (a different digest means a change)
- Content addressing in Git, IPFS, and content-addressable storage (the hash is the address)
- Deduplicating data — identical content yields identical hashes
- A building block inside keyed HMACs or digital signatures
Worked example
Hashing the single line hello gives:
Input: hello
MD5: 5d41402abc4b2a76b9719d911017c592
SHA-1: aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d
SHA-256: 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
Notice how the three algorithms return different-length digests for the same input, and how changing one character would scramble every digest completely. For storage that must resist attackers, prefer SHA-256 (or a salted scheme like bcrypt/Argon2 for passwords).
Frequently asked questions
Is hashing the same as encryption?
No. A hash is a one-way function: you can compute a digest from input but you cannot recover the input from the digest, so there is no decryption. Encryption is reversible with a key; hashing is not reversible at all. That is exactly what makes hashes suitable for verifying data without exposing it.
Which algorithm should I use?
Prefer SHA-256. MD5 (128-bit) and SHA-1 (160-bit) are considered broken because practical collision attacks exist, so they must not be used for security. SHA-256 produces a 256-bit digest with no known practical collision attack and is the current industry default for integrity and signatures.
Why are MD5 and SHA-1 still shown?
For compatibility and checksum verification of legacy systems. Many older file-integrity lists, ROM dumps, and download mirrors still publish MD5 or SHA-1 sums, so the tool computes them for matching purposes only, not for new security work.
Are hashes safe for storing passwords?
A plain hash is not enough. Use a slow, salted password-hashing scheme such as bcrypt, scrypt, or Argon2. SHA-256 alone is too fast and would let an attacker test billions of guesses per second against a stolen hash table.
Does hashing run in my browser?
Yes. This tool uses the Web Crypto SubtleCrypto API (crypto.subtle.digest), which computes SHA-256 and SHA-1 natively in the browser. The input never leaves your device.
ν΄μ μμ±κΈ°λ?
μνΈνμ ν΄μ ν¨μλ 1λ°μ΄νΈ, ν μ€νΈ νμΌ, μ GB λμ€ν¬ μ΄λ―Έμ§ λ± μμ ν¬κΈ°μ μ λ ₯μ λ°μ κ³ μ κΈΈμ΄μ μμ μ§λ¬ΈμΈ λ€μ΄μ μ€νΈλ₯Ό λ°νν©λλ€. κ°μ μ λ ₯μ νμ κ°μ λ€μ΄μ μ€νΈλ₯Ό λ΄κ³ , 1λΉνΈλ§ λ€μ§νλ μμ ν λ€λ₯Έ λ€μ΄μ μ€νΈκ° λμ΅λλ€. μ΄ λꡬλ MD5, SHA-1, SHA-256μ λμμ κ³μ°νλ©°, λͺ¨λ μ²λ¦¬λ λΈλΌμ°μ μ Web Crypto SubtleCrypto APIλ‘ μ΄λ£¨μ΄μ Έ μ λ ₯μ΄ κΈ°κΈ°λ₯Ό λ λμ§ μμ΅λλ€.
μλ λ°©μ
κ° μκ³ λ¦¬μ¦μ κ³ μ λ λΉνΈ κΈΈμ΄μ λ€μ΄μ μ€νΈλ₯Ό λ
λλ€. MD5λ 128λΉνΈ(16μ§μ 32λ¬Έμ), SHA-1μ 160λΉνΈ(16μ§μ 40λ¬Έμ), SHA-256μ 256λΉνΈ(16μ§μ 64λ¬Έμ)μ
λλ€. λ€μ΄μ μ€νΈλ 16μ§μ ν
μ€νΈλ‘ ννλλλ°, κ° λ°μ΄νΈκ° 0–9/a–f λ λ¬Έμλ‘ κΉλν λμλκΈ° λλ¬Έμ
λλ€. μ΄ μκ³ λ¦¬μ¦ λλΆλΆμ λ¨Έν΄–λ΄κ³ (Merkle–Damgård) ꡬ쑰 μμ ꡬμΆλ©λλ€. μ
λ ₯μ 512λΉνΈ λΈλ‘μ λ°°μλ‘ ν¨λ©νκ³ κΈΈμ΄ μ λ―Έμ¬λ₯Ό λΆμΈ λ€, λ©μμ§λ₯Ό ν λΈλ‘μ© μμΆ ν¨μλ‘ μ²λ¦¬ν΄ κ° λΈλ‘μ λμ μνμ μ μ΅λλ€. κ·Έ μ΅μ’
μνκ° λ€μ΄μ μ€νΈμ
λλ€.
κ²°μ μ μΈ λ³΄μ μμ±μ μΆ©λ μ ν(collision resistance)μ λλ€. κ°μ λ€μ΄μ μ€νΈλ₯Ό λ΄λ λ κ°μ μλ‘ λ€λ₯Έ μ λ ₯μ μ°Ύλ κ²μ΄ νμ€μ μΌλ‘ λΆκ°λ₯ν΄μΌ ν©λλ€. MD5μ SHA-1μ μ€μ©μ μΈ μΆ©λ κ³΅κ²©μ΄ μ‘΄μ¬ν΄ κΉ¨μ§ κ²μΌλ‘ κ°μ£Όλλ©°, κ°μΉκ° μλ κ²μ 보νΈνλ λ° μ°λ©΄ μ λ©λλ€. SHA-256μ μλ €μ§ μ€μ©μ μΆ©λ κ³΅κ²©μ΄ μμ΄ νμ¬ κΈ°λ³Έκ°μ λλ€. κ²°μ μ μΌλ‘ ν΄μλ λ¨λ°©ν₯μ λλ€. 볡νΈνκ° μμ΅λλ€. λ°μ΄ν°λ‘λΆν° λ€μ΄μ μ€νΈλ κ³μ°ν μ μμ΄λ λ€μ΄μ μ€νΈλ‘λΆν° λ°μ΄ν°λ₯Ό 볡ꡬν μ μμΌλ©°, κ·Έλμ λ¬΄κ²°μ± κ²μ¬μ μ½ν μΈ μ΄λλ μ±μ μ ν©ν©λλ€.
μμ£Ό μ°λ κ²½μ°
- νμΌ λ¬΄κ²°μ± κ²μ¦ — λ€μ΄λ‘λμ λ€μ΄μ μ€νΈλ₯Ό 곡κ°λ 체ν¬μ¬κ³Ό λΉκ΅
- μ€μ , λ‘κ·Έ, λ°±μ μ λ³κ²½ κ°μ§ (λ€μ΄μ μ€νΈκ° λ€λ₯΄λ©΄ λ³κ²½λ κ²)
- Git, IPFS, μ½ν μΈ μ£Όμ κ°λ₯ μ μ₯μμ μ½ν μΈ μ΄λλ μ± (ν΄μκ° κ³§ μ£Όμ)
- λ°μ΄ν° μ€λ³΅ μ κ±° — κ°μ μ½ν μΈ λ κ°μ ν΄μ
- ν€κ° μλ HMACμ΄λ λμ§νΈ μλͺ μ κ΅¬μ± μμλ‘ μ¬μ©
μ¬μ© μ
λ¨μΌ μ€ helloλ₯Ό ν΄μ±νλ©΄:
Input: hello
MD5: 5d41402abc4b2a76b9719d911017c592
SHA-1: aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d
SHA-256: 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
κ°μ μ λ ₯μ λν΄ μΈ μκ³ λ¦¬μ¦μ΄ μλ‘ λ€λ₯΄κ³ κΈΈμ΄λ λ€λ₯Έ λ€μ΄μ μ€νΈλ₯Ό λ΄λ κ², κ·Έλ¦¬κ³ ν κΈμλ§ λ°κΏλ λͺ¨λ λ€μ΄μ μ€νΈκ° μμ ν λ€μμ΄λ μ μ νμΈνμΈμ. 곡격μ λ§μμΌ νλ μ μ₯μλ SHA-256μ(λΉλ°λ²νΈλΌλ©΄ bcrypt/Argon2 κ°μ μνΈ λ°©μμ) κΆμ₯ν©λλ€.
μμ£Ό 묻λ μ§λ¬Έ
ν΄μκ° μνΈνμ κ°μ 건κ°μ?
μλλλ€. ν΄μλ λ¨λ°©ν₯ ν¨μμ λλ€. μ λ ₯μΌλ‘ λ€μ΄μ μ€νΈλ κ³μ°ν μ μμ΄λ λ€μ΄μ μ€νΈμμ μ λ ₯μ 볡ꡬν μ μμΌλ―λ‘ λ³΅νΈνκ° μμ΅λλ€. μνΈνλ ν€λ‘ κ°μμ μ΄μ§λ§ ν΄μλ μ ν κ°μμ μ΄μ§ μμ΅λλ€. κ·Έλμ λ°μ΄ν°λ₯Ό λ ΈμΆνμ§ μκ³ κ²μ¦νλ μ©λμ λ± λ§μ΅λλ€.
μ΄λ€ μκ³ λ¦¬μ¦μ μ¨μΌ νλμ?
SHA-256μ κΆμ₯ν©λλ€. MD5(128λΉνΈ)μ SHA-1(160λΉνΈ)μ μ€μ©μ μΆ©λ κ³΅κ²©μ΄ μ‘΄μ¬ν΄ 보μ μ©λλ‘λ κΉ¨μ§ κ²μΌλ‘ κ°μ£Όλ©λλ€. SHA-256μ μλ €μ§ μ€μ©μ μΆ©λ κ³΅κ²©μ΄ μλ 256λΉνΈ λ€μ΄μ μ€νΈλ₯Ό λ΄λ©° 무결μ±κ³Ό μλͺ μ νμ¬ μ°μ κΈ°λ³Έκ°μ λλ€.
μ MD5μ SHA-1λ μ¬μ ν λ³΄μ¬ μ£Όλμ?
λ κ±°μ μμ€ν κ³Όμ νΈν λ° μ²΄ν¬μ¬ κ²μ¦ λλ¬Έμ λλ€. μ€λλ νμΌ λ¬΄κ²°μ± λͺ©λ‘, ROM λ€ν, λ€μ΄λ‘λ λ―Έλ¬ λ§μ κ³³μ΄ μ¬μ ν MD5λ SHA-1 ν©κ³λ₯Ό κ²μνλ―λ‘, μ΄ λꡬλ μΌμΉ νμΈ λͺ©μ μΌλ‘λ§ κ³μ°νλ©° μ 보μ μ©λλ‘λ μ°μ§ μμ΅λλ€.
λΉλ°λ²νΈ μ μ₯μ ν΄μκ° μμ νκ°μ?
νλ¬Έ ν΄μλ§μΌλ‘λ λΆμ‘±ν©λλ€. bcrypt, scrypt, Argon2 κ°μ λλ¦¬κ³ μνΈκ° μλ λΉλ°λ²νΈ ν΄μ λ°©μμ μ¬μ©νμΈμ. SHA-256 λ¨λ μ λ무 λΉ¨λΌμ ν΄μ ν μ΄λΈμ νμ·¨ν 곡격μκ° μ΄λΉ μμμ΅ λ²μ μΆμΈ‘μ μλν μ μμ΅λλ€.
ν΄μ±μ΄ μ λΈλΌμ°μ μμ μ€νλλμ?
λ€. μ΄ λꡬλ λΈλΌμ°μ μμ SHA-256κ³Ό SHA-1μ λ€μ΄ν°λΈλ‘ κ³μ°νλ Web Crypto SubtleCrypto API(crypto.subtle.digest)λ₯Ό μ¬μ©ν©λλ€. μ
λ ₯μ κΈ°κΈ°λ₯Ό λ λμ§ μμ΅λλ€.