All tools / Buying guides / SHA-1 vs SHA-256 vs SHA-512: how to choose

SHA-1 vs SHA-256 vs SHA-512: how to choose

The short answer

Use SHA-256 for anything new. SHA-1 was practically broken by a collision attack in 2017 and must not be used for security any more. SHA-512 is stronger but slower on 32-bit platforms and short messages — it only pays off when you need a longer digest or run on 64-bit hardware.

Key differences

AspectSHA-1SHA-256SHA-512
Digest length160 bit (40 hex chars)256 bit (64 chars)512 bit (128 chars)
Security statusBroken — do not useSecure — current standardSecure — larger margin
Practical collision attackDemonstrated (SHAttered, 2017)NoneNone
32-bit performanceFastFastSlower
64-bit performanceFastFastComparable to or faster than SHA-256
Where it belongsLegacy checksums only (never security)Signatures, certificates, checksums, key derivationLong-digest needs, 64-bit servers

SHA-1

Once the default choice. In 2017 Google and CWI produced two different PDF files with the same SHA-1 digest (SHAttered), which formally ended its security life. Browsers and certificate authorities have dropped it entirely. Do not let it appear in new code unless you are talking to a legacy system you cannot change.

SHA-256 / SHA-512

Both are SHA-2 family and neither has a known practical attack. SHA-256 is the de facto standard: TLS certificates, code signing, file checksums, JWTs. SHA-512 produces a longer digest with a bigger post-quantum margin and is even faster than SHA-256 on 64-bit CPUs with long messages, but it slows down noticeably on 32-bit hardware (some embedded and older devices). For password storage neither is right — use bcrypt, scrypt or Argon2.

How to choose

Related tools

FAQ

Why is a SHA-256 output 64 characters

It is a 256-bit digest written as two hex characters per byte: 256 / 8 x 2 = 64 characters.

Is SHA-512 always more secure than SHA-256

In theory it has more collision resistance, but against every attack that actually exists today both are comfortably out of reach. Pick based on platform performance and ecosystem support.

Can I hash user passwords

No. SHA is designed to be fast, which is exactly what brute force wants. Password storage needs a dedicated slow hash: Argon2, bcrypt or scrypt.