SHA-1 Hash Generator
Calculate the SHA-1 hash of any string instantly in your browser. SHA-1 produces a 160-bit hash, but a collision was demonstrated by the SHAttered attack in 2017, making it unsuitable for new applications.
What Is a SHA-1 Hash?
SHA-1 is a hash function that computes a fixed 160-bit value from data of any length. The output is expressed as 40 hexadecimal characters, and the same input always yields the same value. This tool computes the SHA-1 hash of the string you enter, in your browser and in real time. What you type is never sent anywhere.
That said, SHA-1 cannot be used for new security purposes. In 2017 an attack was demonstrated that deliberately produces the same hash from two different files. For signatures, certificates and password storage, choose SHA-256 or stronger. The use of this tool is limited to checking against values produced by existing systems and to observing how the algorithm behaves.
Steps to Compute a SHA-1 Hash
- Enter a string Type the string you want hashed. It is computed as you type and the result appears.
- Check the result Forty hexadecimal characters are displayed. Change even one character of the input and the value becomes entirely different.
- Copy it and compare The copy button puts it on your clipboard, ready to check against an existing value.
Tips for getting more out of it
- SHA-1 (Secure Hash Algorithm 1) was designed by the NSA and standardized by NIST in 1995. It produces a 160-bit hash represented as 40 hexadecimal characters.
- In 2017, Google and CWI Amsterdam published the SHAttered attack, producing two different PDF files with identical SHA-1 hashes — definitively ending SHA-1's credibility for security use.
- Major browsers have treated SHA-1 signatures in SSL/TLS certificates as invalid since 2017. Git has historically used SHA-1 for commit identification and is now migrating to SHA-256.
- You may still encounter SHA-1 in Git commit hashes, but since Git does not rely on hashes for security guarantees, the practical impact remains limited for now.
- For any new system design, choose SHA-256 or stronger instead of SHA-1.
When a SHA-1 Hash Calculation Comes in Handy
Checking against an existing system's values
Confirm whether you match the value produced by a system still running on SHA-1. Useful for verification during a migration.
Understanding Git hashes
Generate the same 40-character format as a commit ID and see it for yourself. It helps in grasping what values Git is working with.
Preparing test data for an implementation
When you have implemented hashing, you can prepare known values here to use as expected results.
Observing the properties of a hash function
Watch for yourself how changing a single character of the input transforms the output completely.
Hash Terms Explained
- SHA-1
- A function that produces a 160-bit hash. It was standardised in 1995, but its security has since been broken.
- Collision
- The state in which two different pieces of data produce the same hash. For SHA-1 it was demonstrated that collisions can be constructed deliberately.
- SHAttered
- The name of the collision attack on SHA-1 published in 2017. Two PDFs sharing the same hash were actually produced.
- Hexadecimal Notation
- A way of representing numbers with the symbols 0 through F. SHA-1's 160 bits are expressed as 40 hexadecimal characters.
- SHA-256
- A function that produces a 256-bit hash. It is still regarded as secure, and for new purposes you should choose this or stronger.
FAQ
Side Note — SHAttered: A Collision Attack 9.2 Quintillion Operations in the Making
In February 2017, Google and CWI Amsterdam announced the "SHAttered" collision attack. Producing two different PDFs with the same SHA-1 hash required a computation equivalent to running 99,000 CPU cores on Google Cloud Platform for more than two years.
The moment SHA-1 moved from "theoretically breakable" to "actually broken." GitHub, Google, and other major services immediately accelerated the deprecation of SHA-1 dependencies. Git formally launched a migration plan to SHA-256 for commit identification.
Despite being "broken," SHA-1 implementations remain in use worldwide. Embedded devices and legacy enterprise systems are notoriously difficult to update, making the full retirement of SHA-1 an ongoing industry-wide challenge.