SHA-1 vs SHA-256 vs SHA-512: how to choose
Use SHA-256 for anything new. SHA-1 was practically broken by a collision attack in 2017 and must not be used for security any more. SHA-512 is stronger but slower on 32-bit platforms and short messages — it only pays off when you need a longer digest or run on 64-bit hardware.
Key differences
| Aspect | SHA-1 | SHA-256 | SHA-512 |
|---|---|---|---|
| Digest length | 160 bit (40 hex chars) | 256 bit (64 chars) | 512 bit (128 chars) |
| Security status | Broken — do not use | Secure — current standard | Secure — larger margin |
| Practical collision attack | Demonstrated (SHAttered, 2017) | None | None |
| 32-bit performance | Fast | Fast | Slower |
| 64-bit performance | Fast | Fast | Comparable to or faster than SHA-256 |
| Where it belongs | Legacy checksums only (never security) | Signatures, certificates, checksums, key derivation | Long-digest needs, 64-bit servers |
SHA-1
Once the default choice. In 2017 Google and CWI produced two different PDF files with the same SHA-1 digest (SHAttered), which formally ended its security life. Browsers and certificate authorities have dropped it entirely. Do not let it appear in new code unless you are talking to a legacy system you cannot change.
SHA-256 / SHA-512
Both are SHA-2 family and neither has a known practical attack. SHA-256 is the de facto standard: TLS certificates, code signing, file checksums, JWTs. SHA-512 produces a longer digest with a bigger post-quantum margin and is even faster than SHA-256 on 64-bit CPUs with long messages, but it slows down noticeably on 32-bit hardware (some embedded and older devices). For password storage neither is right — use bcrypt, scrypt or Argon2.
How to choose
- File checksums, API signatures, certificates → SHA-256
- You need the longest digest, or a 64-bit server → SHA-512
- Storing passwords → Neither — use Argon2 / bcrypt / scrypt
Related tools
FAQ
Why is a SHA-256 output 64 characters
It is a 256-bit digest written as two hex characters per byte: 256 / 8 x 2 = 64 characters.
Is SHA-512 always more secure than SHA-256
In theory it has more collision resistance, but against every attack that actually exists today both are comfortably out of reach. Pick based on platform performance and ecosystem support.
Can I hash user passwords
No. SHA is designed to be fast, which is exactly what brute force wants. Password storage needs a dedicated slow hash: Argon2, bcrypt or scrypt.