Have you ever downloaded software and seen something like “SHA-256: 2cf24dba…” on the official site, wondering what that long string of characters is? It is a hash (also called a checksum), and it exists so you can verify that the file you downloaded is genuine. When you are worried about malware or tampered files, this check matters a lot.
In this guide, we explain what a hash is, how SHA-256 works, and how to verify a downloaded file step by step. You will also learn how MD5 and SHA-1 differ, and how to use a free browser-based hash generator.
What is a hash?
A hash (strictly, a cryptographic hash function) is a function that computes a fixed-length “fingerprint” from data of any size. For example, the five-letter text “hello” produces this 64-character value with SHA-256:
SHA-256 of "hello" =
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
Hashes have three key properties:
- The same data always produces the same value
- Even a tiny change in content produces a completely different value (change “hello” to “hellp” and the hash changes dramatically)
- The original data cannot be recovered from the hash (one-way function)
These “fingerprint-like” properties make hashes useful for verifying data integrity and detecting tampering.
Terminology: "computing a hash" is also called "hashing" or "taking a digest." The resulting value is known as the "hash value" or "digest."
Hash functions compared
Different hash functions produce different output lengths and have different levels of security.
| Function | Output | Security | Current status |
|---|---|---|---|
| MD5 | 128 bits | Low | Not recommended (collisions found) |
| SHA-1 | 160 bits | Low | Not recommended (known weaknesses) |
| SHA-256 | 256 bits | High | Recommended (most common) |
| SHA-512 | 512 bits | High | Recommended (longer than SHA-256) |
Today, SHA-256 is the standard choice for verifying files and for security purposes. MD5 and SHA-1 were widely used in the past, but “collisions” — different data producing the same hash — were discovered, so they are no longer considered safe.
Heads up: MD5 and SHA-1 hashes still appear in legacy systems, but do not rely on them where security matters. If an official site lists SHA-256, use a tool that can compute SHA-256 rather than a tool that only outputs MD5.
Where hashes are used
Hashes are everywhere, often without you noticing:
- Verifying downloads: compare the hash published on the official site with the hash of the file you downloaded
- Storing passwords: services store hashed passwords instead of plaintext
- Detecting tampering: compare hashes of sent and received data to confirm nothing changed
- Blockchain: used to keep transaction data consistent
File verification is especially important when downloading software. If a distribution site has been compromised, comparing the file’s hash against the legitimate one reveals the fake.
How to verify a downloaded file with SHA-256
The verification workflow is simple:
Find the official hash
On the software's official site or download page, copy the 64-character value listed under "SHA-256".
Compute the hash of your file
Select the downloaded file in a hash generator tool and choose SHA-256.
Compare the two values
If they match exactly, the file is genuine. If they differ even slightly, the file may be corrupted or tampered with.
Quick comparison tip: eyeballing 64 characters is tedious, so focus on the first eight and last eight characters. If you want to be thorough, paste both values into a text comparison tool.
Things to keep in mind
1. A hash is not encryption
Hashing is a one-way transformation, not encryption. Encrypted data can be decrypted with a key, but a hash cannot be reversed to recover the original data. This is why services store password hashes — although simple passwords can still be guessed by dictionary attacks, which is why real systems combine hashing with a random “salt.”
2. Uppercase and lowercase hashes are the same
SHA-256 hashes are written in hexadecimal and usually shown in lowercase (“2cf24dba…”). Uppercase (“2CF24DBA…”) represents the same value, so do not worry if the cases differ when comparing.
3. Compute hashes on your device
Uploading a file to an online service to hash it hands your file to a third party. A tool that computes the hash entirely in your browser keeps your file private.
How to use the Tools Hub hash generator
For file verification, you do not need a command line. The Tools Hub hash generator computes hashes in your browser — select a file and it is done. It also hashes text and supports SHA-1, SHA-256, SHA-384 and SHA-512.
How to use it (three steps)
Choose your input
Pick "Text" or "File" as the input type and enter the content you want to hash.
Pick an algorithm
Choose SHA-256 (recommended), SHA-1, SHA-384 or SHA-512. For file verification, use the same algorithm the official site lists.
Calculate and compare
Press "Calculate hash" and compare the result with the official value. Copy it and paste it into a comparison tool if needed.
The tool from this guide
Hash Generator
Free, no sign-up required, and your files are processed entirely in your browser.
Summary
- A hash is a fixed-length “fingerprint” of data; the same data always yields the same value
- Even a tiny change in content produces a completely different hash, and the original cannot be recovered
- SHA-256 is the current recommendation; MD5 and SHA-1 are considered insecure
- Verifying a download means comparing the official hash with the hash you computed
- A hash is not encryption; password storage uses hashing with salt
- A browser-based tool keeps your file private — nothing is uploaded
Hashing sounds technical, but think of it as a “fingerprint for data” and the use case becomes simple. Next time you download an important file, take a moment to verify it.
FAQ
What is a hash?
A hash is the output of a function that computes a fixed-length value from data. The same data always produces the same value, and any change in content produces a different one. Hashes are used to verify data integrity and detect tampering.
What is the difference between MD5 and SHA-256?
Their output length and security differ. MD5 produces 128 bits and has known collisions, so it is not recommended. SHA-256 produces 256 bits and is the current standard. Use SHA-256 or stronger for security purposes.
How do I verify a downloaded file?
① Copy the SHA-256 value from the official site. ② Compute the SHA-256 of the downloaded file with a hash generator. ③ Compare the two values — an exact match means the file is genuine.
Is a hash the same as encryption?
No. Encryption can be reversed with a key, but a hash is a one-way transformation. The original data cannot be recovered from a hash.