Glossary

SHA-256

SHA-256 is a cryptographic hash function that takes an input of any length and produces a fixed 256-bit (32-byte) digest, conventionally shown as 64 hexadecimal characters. It's part of the SHA-2 family, standardized by NIST in FIPS 180-4, and is the de facto default hash function for new systems today — used in TLS certificates, Bitcoin's proof-of-work, and Git's newer SHA-256 object-hashing mode.

How it works

SHA-256 processes input in 512-bit blocks through 64 rounds of bitwise operations (rotations, XOR, modular addition) built on the Merkle–Damgård construction, producing the same 32-byte output length regardless of input size — hashing one byte or one gigabyte both yield a 64-character hex digest. It's a one-way function: computing the hash is fast, but recovering the input from the digest is computationally infeasible. It's also deterministic (same input always produces the same output) and exhibits the avalanche effect — changing a single input bit flips roughly half the output bits.

Example:

SHA-256("abc") =
ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

Common pitfalls

  • SHA-256 alone is unsuitable for hashing passwords — it's too fast, which makes brute-forcing feasible at scale. Use a purpose-built slow hash (bcrypt, scrypt, Argon2) instead.
  • Two different files producing the same SHA-256 digest (a collision) has never been demonstrated and is currently considered computationally infeasible — unlike MD5 or SHA-1, which are broken in this respect.
  • A matching checksum only proves data integrity, not authenticity — anyone can recompute a SHA-256 hash for tampered data unless it's combined with a secret key (see HMAC) or a digital signature.
  • Hex-encoding case doesn't matter cryptographically, but a byte-for-byte string comparison of two digests will fail if one is uppercase and the other lowercase.

Related terms

  • SHA-1 — the older, now-broken hash function SHA-256 effectively replaced.
  • MD5 — an even older, faster, and more thoroughly broken hash still seen in legacy checksums.
  • HMAC — wraps SHA-256 with a secret key to add authenticity on top of integrity.
  • UUID — version 5 UUIDs use SHA-1 rather than SHA-256, but both are namespace-based hashing schemes for generating deterministic IDs.

See also

  • Tool: Hash Generator — compute MD5, SHA-1, SHA-256, and SHA-512 digests from text and compare hashes to verify data integrity.