SHA-256 maps these 43 bytes to a 256-bit digest. Flipping a single input bit changed 141 of the 256 digest bits (55.1%), so near-identical inputs get unrelated digests.
Avalanche test, SHA-256 (first 64 of 256 bits)
Digest of the input
1
1
0
1
0
1
1
1
1
0
1
0
1
0
0
0
1
1
1
1
1
0
1
1
1
0
1
1
0
0
1
1
0
0
0
0
0
1
1
1
1
1
0
1
0
1
1
1
1
0
0
0
0
0
0
0
1
0
0
1
0
1
0
0
Digest with bit 0 of byte 1 flipped
1
0
0
0
1
0
1
0
1
1
0
0
1
1
1
0
0
0
1
0
1
1
0
1
0
0
1
1
1
0
0
1
0
0
0
1
0
1
1
0
0
1
1
0
0
0
0
1
0
0
0
0
0
1
1
1
0
1
1
0
1
1
1
1
Bits that differ
0
1
0
1
1
1
0
1
0
1
1
0
0
1
1
0
1
1
0
1
0
1
1
0
1
0
0
0
1
0
1
0
0
0
0
1
0
0
0
1
1
0
1
1
0
1
1
0
1
0
0
0
0
1
1
1
1
1
1
1
1
0
1
1
Share of digest bits changed by a one-bit input change
How it's calculated S
Encode the text as UTF-8
43 characters → 43 bytes (344 bits).
Pad to whole blocks
blocks=⌊64n+8⌋+1=⌊6443+8⌋+1=1
Append a 1 bit, zeros, and the 64-bit message length so the padded message is a multiple of 512 bits.
Run the compression function
1block×64rounds=64rounds
Each block updates a state of eight 32-bit words, which is added back into the running state after the block.
A cryptographic hash turns any input into a fixed-size digest: 128 bits for MD5, 160 for SHA-1, 256 for SHA-256 and 512 for SHA-512, while CRC-32 is a 32-bit error-detecting checksum. The text is encoded as UTF-8, padded to whole 512-bit or 1024-bit blocks, and run through the algorithm's compression rounds as NIST FIPS 180-4 and RFC 1321 specify.
People use it to verify downloads against a published checksum, compare files and test their own code. The default sentence, "The quick brown fox jumps over the lazy dog", has the SHA-256 digest d7a8fbb3…37c9e592, and flipping one input bit changes 141 of its 256 bits, close to the half a good hash should change.
MD5 and SHA-1 have practical collision attacks, so use SHA-256 or SHA-512 wherever someone could tamper with the data.
Checked against: FIPS 180-4 / NIST CSRC SHA-1, SHA-256, SHA-512 examples for “abc”; RFC 1321 §A.5 MD5 test suite; all five re-checked with Python 3.8 hashlib and binascii.crc32
Checked against: FIPS 180-4 / NIST CSRC SHA-512 two-block example; re-checked with Python 3.8 hashlib.sha512
Questions
Is MD5 still safe to use?
Not for security. Practical MD5 collisions were published in 2004, and in 2008 researchers used them to forge a trusted certificate authority certificate. RFC 6151 (2011) says MD5 is no longer acceptable where collision resistance is required, such as digital signatures. It still catches accidental corruption in a download, but use SHA-256 or SHA-512 from NIST FIPS 180-4 for anything an attacker could alter.
What is the difference between SHA-1 and SHA-256?
SHA-256 produces a 256-bit digest (64 hex digits) against SHA-1's 160 bits (40 hex digits), and unlike SHA-1 it has no known practical collision attack. Google and CWI Amsterdam published the first SHA-1 collision, SHAttered, in 2017, and NIST has announced that SHA-1 is to be phased out of all its uses by 31 December 2030. Both belong to FIPS 180-4.
How do I verify a file's checksum?
Hash the downloaded file and compare the result with the checksum the publisher lists; any difference means the file changed. On Linux run sha256sum file, on macOS shasum -a 256 file, and on Windows certutil -hashfile file SHA256 or PowerShell's Get-FileHash, which uses SHA-256 by default. The comparison box here does the same for text and ignores case and spaces.
Why does echo text | sha256sum give a different hash?
Because echo adds a line feed, so the command hashes abc plus a newline (4 bytes) rather than abc (3 bytes), and one extra byte changes the whole digest: SHA-256 of abc starts ba7816bf, while abc with a line feed starts edeaaff3. Use echo -n or printf '%s' to hash the text alone, or turn on the line-feed option here to match echo.
Can two different inputs have the same hash?
Yes, because unlimited inputs map to a fixed number of digests, but for a secure hash nobody should be able to find such a pair. By the birthday bound, a brute-force search needs about 2^(n/2) tries for an n-bit digest: 2^64 for MD5 and 2^128 for SHA-256. Known attacks find MD5 and SHA-1 collisions far faster, and CRC-32 collisions can be computed directly because CRC is linear.
How accurate is the hash generator and checksum calculator?
Accuracy depends on your inputs and the method's assumptions. Decimal arithmetic uses 50 significant digits, but estimates, numerical methods and source data can be less precise; the displayed rounding does not remove those limits. It is checked against 11 worked examples whose answers come from independent sources; for example, ““abc” (FIPS 180-4 one-block example)” is checked against FIPS 180-4 / NIST CSRC SHA-1, SHA-256, SHA-512 examples for “abc”; RFC 1321 §A.5 MD5 test suite; all five re-checked with Python 3.8 hashlib and binascii.crc32.
Where does the method come from?
NIST FIPS 180-4, Secure Hash Standard (SHA-1, SHA-256, SHA-512); RFC 1321 — The MD5 Message-Digest Algorithm; NIST CSRC — Examples with intermediate values (SHA-1, SHA-2); Catalogue of parametrised CRC algorithms — CRC-32/ISO-HDLC.