Hash functions
A cryptographic hash function turns any input into a fixed-size fingerprint (digest). The same input always gives the same digest, and a tiny change produces a completely different one. Common uses are checksums for downloads, cache keys, deduplication and data integrity checks.
| Algorithm | Digest size | Use for security? |
|---|---|---|
| MD5 | 128 bit | No: broken, checksums only |
| SHA-1 | 160 bit | No: collisions are practical |
| SHA-256 | 256 bit | Yes |
| SHA-384 | 384 bit | Yes |
| SHA-512 | 512 bit | Yes |
HMAC
An HMAC combines a hash with a secret key. It proves a message came from someone who knows the key and was not modified. Webhooks (GitHub, Stripe, …) sign payloads with HMAC-SHA256.
Do not use plain hashes to store passwords. Use a slow password hash such as Argon2, scrypt or bcrypt.