Cryptography Basic

Hash Function Explorer

A hash turns any input into a fixed-length fingerprint. Type to see it change, flip a single character to watch half the output bits flip with it, and find a genuine collision in a shortened hash to see why output length is the whole story.

SHA-1 / 256 / 384 / 512
Live avalanche meter
Real collision search
Live
Message
Input length43 characters
Output length256 bits / 64 hex
Collision resistance2128 by birthday bound
Hashing happens entirely in your browser via the Web Crypto API. Nothing is uploaded anywhere.
Digest
SHA-256
—
Compare with a second message
Second digest — differing hex characters in red
—
Avalanche: bits changed
—
First 128 output bits — red means the bit flipped
Find a Real Collision

A full SHA-256 collision is out of reach. Truncate the digest to a handful of bits, though, and the birthday bound bites immediately: about 2n/2 tries suffice for an n-bit hash, not 2n. This searches for two different inputs whose truncated digests match.

Notice how close the number of attempts sits to √(2n). That square root is why a hash needs 256 bits of output to deliver 128 bits of collision resistance — and why 128-bit hashes such as MD5 are finished.

What a Hash Function Must Do
H : any input -> fixed-length digest

Preimage resistance. Given a digest, you cannot find any input producing it. This is what lets a server store hashed passwords instead of real ones.

Second preimage resistance. Given one message, you cannot find a different one with the same digest. This is what makes a hash usable as a fingerprint for a file.

Collision resistance. You cannot find any two messages that hash alike. This is the hardest requirement and the first to fall — because of the birthday bound, it only ever gives half the output length in security.

The avalanche effect ties them together: change one input bit and roughly half the output bits flip, with no visible relationship between the two digests.

A digest is not encryption. There is no key and no way back — hashing is deliberately one-way, and that is the entire point.
Which Ones Are Still Safe

Hash functions have a history of falling, and the pattern is always the same: theoretical weakness first, practical collisions later.

  • MD5 — broken. Collisions are found in seconds on a laptop. It has been unusable for signatures since 2004 and still turns up in old systems.
  • SHA-1 — broken. Google and CWI produced two different PDFs with the same digest in 2017 (the SHAttered attack). Browsers dropped it from certificates; it is in the dropdown above so you can see it, not so you can use it.
  • SHA-256 and SHA-512 — fine. No practical attack, and they are the current default nearly everywhere.
  • SHA-3 — fine, and structurally different. A sponge construction rather than Merkle-Damgård, chosen deliberately so that a break of the SHA-2 family would not carry over.
For passwords, none of these is enough on its own — they are far too fast. Use bcrypt, scrypt or Argon2, which are deliberately slow and salted.
Put It Into Practice

The tool shows the mechanism — the slides show why it is built that way.

Hashing, signatures and integrity

Hash functions sit under passwords, signatures, blockchains and file verification. One-on-one tutoring covers what they guarantee, what they never promised, and how the famous breaks actually worked.

Book a Free Consultation →