Developer

How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption

ToolOrbit Engineering 2 min readUpdated
How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption

A cryptographic hash function turns any input into a fixed-length fingerprint. The same input always produces the same output, but even a one-character change produces a completely different result, and you cannot run the function backwards to recover the original. The ToolOrbit Hash Generator computes these digests using the browser-native Web Crypto API, so your data never leaves your device.

How hashing works

Hashing is deterministic and one-way. It is used to verify integrity, detect changes, and compare values without storing the originals. A hash is not encryption, because there is no key and no way to decrypt it. It is also distinct from password hashing, which deliberately adds salting and slowness.

Input:  hello
SHA-256: 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824

Choosing an algorithm

  • SHA-256: the modern default for checksums, signatures, and integrity verification
  • SHA-384 and SHA-512: longer digests for higher security margins or 64-bit performance
  • SHA-1: still seen in legacy systems and Git object IDs, but considered broken for security
  • Avoid MD5 and SHA-1 for anything where an attacker could craft collisions
Warning: Never use a plain SHA hash to store user passwords. Use a purpose-built password hash like bcrypt, scrypt, or Argon2, which are intentionally slow and salted.

Using the Hash Generator

Paste your text and instantly see the digest in each algorithm, ready to copy. A common workflow is verifying a downloaded file or release: compute the hash and compare it character by character against the checksum the publisher provided. Because the Web Crypto API runs in your browser, even sensitive input stays private.

Best practices

Use SHA-256 unless you have a specific reason not to, compare hashes in full rather than by eye where possible, and treat any system still relying on MD5 or SHA-1 for security as a candidate for upgrade. For integrity checks, that fingerprint is all you need.

Hashing vs encryption — the distinction that matters

Hashing is one-way and fixed-length: the same input always yields the same digest, but you cannot recover the input from it. Encryption is two-way — anyone with the key can read the original. That is why passwords are stored hashed (plus a per-user salt so two identical passwords do not collide) and files are encrypted instead. Use the hash for integrity and identity checks, never to protect data someone must later read.

  • Verify a downloaded file’s checksum matches the publisher’s published digest.
  • Compare two documents by their hash instead of trusted-tag diffing.
  • Never send or store the raw password — store the salted hash.

Frequently asked questions

Paste the text into the SHA-256 Generator and the digest appears instantly in every SHA variant — SHA-1, SHA-384 and SHA-512 included. All hashing runs in your browser.

No. Encryption is reversible with a key; hashing is one-way. You cannot recover the original input from a hash, which is exactly what makes it useful for integrity checks.


Tools mentioned

More reading

View all guides
What Is Base64? How Encoding Works and Common Mistakes
Developer

What Is Base64? How Encoding Works and Common Mistakes

What Base64 encoding actually does, where it is used, and the mistakes that cause broken or oversized output.

2 min readUpdated
encodeURI vs encodeURIComponent: Which One to Use
Developer

encodeURI vs encodeURIComponent: Which One to Use

How percent-encoding works, the difference between encoding a whole URL and a single component, and the mistakes that break links.

2 min readUpdated
What Is a UUID? Version 4 vs Version 7 Explained
Developer

What Is a UUID? Version 4 vs Version 7 Explained

What a UUID looks like, why version 4 is the safe default, when version 7 is better, and best practices for IDs.

2 min readUpdated
What Is a JWT? Header, Payload and Signature Explained
Developer

What Is a JWT? Header, Payload and Signature Explained

A JSON Web Token has three parts. Learn what the header, payload and signature contain, how to read the claims, and why decoding is not verifying.

2 min readUpdated
What Is HTML Encoding? Entities & Escaping Explained
Developer

What Is HTML Encoding? Entities & Escaping Explained

Learn how HTML encoding works, why escaping prevents XSS and layout breaks, and how to encode and decode named, decimal, and hex entities.

2 min readUpdated
Unix Time Explained: Seconds, Milliseconds and Time Zones
Developer

Unix Time Explained: Seconds, Milliseconds and Time Zones

What a Unix timestamp is, how to tell seconds from milliseconds, how time zones come into it, and the values worth recognising.

2 min readUpdated
Binary, Octal, Decimal and Hex: How Number Bases Work
Developer

Binary, Octal, Decimal and Hex: How Number Bases Work

How positional number bases work, why very large values need exact arithmetic, and the hex and binary values you meet every day.

2 min readUpdated
Regex Basics: How Patterns, Flags and Character Classes Work
Developer

Regex Basics: How Patterns, Flags and Character Classes Work

How a regular expression is built, what the flags change, and the character classes you will use most.

2 min readUpdated