Glossary

SHA-1

SHA-1 (Secure Hash Algorithm 1) is a cryptographic hash function that produces a 160-bit (20-byte) digest, conventionally shown as 40 hexadecimal characters. Designed by the NSA and published by NIST in 1995, it was the dominant general-purpose hash function for over a decade before being broken for security purposes and superseded by SHA-2 (see SHA-256).

How it works

Like other hash functions in its family, SHA-1 processes input in 512-bit blocks through 80 rounds of bitwise operations, always producing the same 20-byte output regardless of input size. In principle it aims for the same properties as SHA-256 — determinism, the avalanche effect, and collision resistance — but the collision-resistance property is where SHA-1 has actually failed in practice.

Example:

SHA-1("abc") = a9993e364706816aba3e25717850c26c9cd0d89d

In February 2017, Google and CWI Amsterdam published the first practical SHA-1 collision ("SHAttered"): two different PDF files that hash to the identical SHA-1 digest, found using roughly 2^63.1 SHA-1 computations — far less work than the 2^80 a secure 160-bit hash should require. Major browsers and certificate authorities had already begun phasing out SHA-1 certificates before that, and the attack removed any remaining justification for new security-relevant use.

Common pitfalls

  • Treat SHA-1 as broken for any security purpose — digital signatures, certificate fingerprints, or anything where an attacker could benefit from crafting a collision.
  • It's still fine for non-adversarial uses like Git's internal object addressing (Git is gradually migrating to SHA-256, but the SHA-1 scheme isn't a security vulnerability in that specific context since Git isn't trying to resist a malicious collision attacker on your own repo).
  • SHA-1 is not "encryption" and was never meant to hide data — like all hash functions here, it's one-way and can't be reversed to recover the input.
  • Some legacy systems still verify SHA-1 checksums for file integrity against accidental corruption, where collision resistance against a deliberate attacker isn't the threat model — that's a reasonable, narrow use case, not a security control.

Related terms

  • MD5 — an even weaker, older hash with practical collisions known since 2004.
  • SHA-256 — the modern replacement with no known practical collision attack.
  • HMAC — can still use SHA-1 as its underlying hash (HMAC-SHA1); the keyed construction is more resistant to the specific collision attacks that break plain SHA-1.
  • UUID — version 5 UUIDs deliberately reuse SHA-1 for deterministic ID generation, a non-adversarial context where collision resistance isn't the point.

See also

  • Tool: Hash Generator — compute SHA-1 digests (alongside MD5, SHA-256, and SHA-512) from text for legacy compatibility checks.