A hash turns any input into a fixed-length fingerprint. Type to see it change, flip a single character to watch half the output bits flip with it, and find a genuine collision in a shortened hash to see why output length is the whole story.
A full SHA-256 collision is out of reach. Truncate the digest to a handful of bits, though, and the birthday bound bites immediately: about 2n/2 tries suffice for an n-bit hash, not 2n. This searches for two different inputs whose truncated digests match.
Notice how close the number of attempts sits to √(2n). That square root is why a hash needs 256 bits of output to deliver 128 bits of collision resistance — and why 128-bit hashes such as MD5 are finished.
H : any input -> fixed-length digest
Preimage resistance. Given a digest, you cannot find any input producing it. This is what lets a server store hashed passwords instead of real ones.
Second preimage resistance. Given one message, you cannot find a different one with the same digest. This is what makes a hash usable as a fingerprint for a file.
Collision resistance. You cannot find any two messages that hash alike. This is the hardest requirement and the first to fall — because of the birthday bound, it only ever gives half the output length in security.
The avalanche effect ties them together: change one input bit and roughly half the output bits flip, with no visible relationship between the two digests.
Hash functions have a history of falling, and the pattern is always the same: theoretical weakness first, practical collisions later.
The tool shows the mechanism — the slides show why it is built that way.
Hash functions sit under passwords, signatures, blockchains and file verification. One-on-one tutoring covers what they guarantee, what they never promised, and how the famous breaks actually worked.