What a hash is
A cryptographic hash turns any input into a fixed-length fingerprint. The same input always gives the same hash, and a tiny change gives a completely different one. The hash cannot be reversed to recover the input.
Which to use
- SHA-256 is the usual choice for checksums and integrity checks.
- SHA-1 is broken for security purposes (collisions are practical). Use it only for legacy compatibility.
- SHA-384 and SHA-512 are longer variants of the same family.
Not for passwords
Plain SHA hashes are too fast for storing passwords. Use a purpose-built password hash such as Argon2, scrypt or bcrypt. Text is hashed as UTF-8.