Hash vs. encryption
A hash is a one-way fingerprint: the same input always produces the same fixed-length output, but you can't reverse it to recover the original. Encryption is two-way — data scrambled with a key can be unscrambled with the right key. Hashes are used wherever you never want the original back: checksums, integrity checks and password verification.
Which algorithm should I use?
- SHA-256 / SHA-512 — the modern, secure defaults. Use these for checksums, file integrity and anything new. SHA-256 is what most download pages publish.
- MD5 / SHA-1 — broken for security: collision attacks have been demonstrated for both (MD5 in 2004, SHA-1 in 2017), so never use them where an attacker is involved — no passwords, no signatures. They're still fine for non-adversarial checksums: dedupe, cache keys, spotting accidental corruption.
- HMAC — a keyed hash: the same algorithm plus a secret key. Two parties sharing the key can verify a message wasn't tampered with or forged. This is what API request signing and webhook verification use.
Passwords need salt and slowness
Never store plain MD5/SHA hashes of passwords — unsalted fast hashes fall to rainbow tables in seconds. Password storage needs a slow, salted construction like bcrypt, scrypt or argon2. This tool is for checksums and dev tasks, not for storing credentials.
Verifying a download
Drop the downloaded file above and compare its SHA-256 against the checksum the publisher lists. If they match, the file is byte-for-byte identical to what was released — any modification, however small, changes the hash completely.