SHA-1 Hash Function Architecture & Mathematical Specification
The sha1 hash function is a cryptographic message authentication and integrity hashing standard specified under NIST FIPS PUB 180-4. As a dedicated hash generator sha1 and sha1 calculator, this tool computes the 160-bit digest by padding the arbitrary input bitstream with a single '1' bit followed by zeros, appending a 64-bit big-endian integer representing the original bit length.
Cryptographic Hash Comparison
| Algorithm |
Digest Bit Length |
Hex Output Length |
Collision Resistance |
Recommended Production Use |
| MD5 (RFC 1321) |
128 bits |
32 chars |
Broken (Instant collision) |
Non-cryptographic checksums only |
| SHA-1 (FIPS 180-4) |
160 bits |
40 chars |
Vulnerable (SHAttered 2017) |
Git commits, BitTorrent, file verification |
| SHA-256 (SHA-2) |
256 bits |
64 chars |
Current NIST standard |
TLS/SSL certificates, Bitcoin, passwords |
| SHA-512 (SHA-2) |
512 bits |
128 chars |
Current NIST standard |
High-security government & financial systems |
Verified SHA-1 Hash Example Vectors
When implementing software cryptography or writing unit tests, developers need authentic sha1 hash example vectors to calibrate their hash generation algorithms:
| Input String |
Expected SHA-1 Hexadecimal Digest |
"" (Empty string) |
da39a3ee5e6b4b0d3255bfef95601890afd80709 |
"The quick brown fox jumps over the lazy dog" |
2fd4e1c67a2d28fced849ee1bb76e7391b93eb12 |
"The quick brown fox jumps over the lazy cog" |
de9f2c7fd25e1b3af57e58a02052d49e1a0725c7 |
"123456" |
7c4a8d09ca3762af61e59520943dc26494f8941b |
Notice how changing a single letter from 'dog' to 'cog' completely changes 95% of the resulting digest bits. This property is known as the Avalanche Effect.
Frequently Asked Questions: SHA1 Hash Calculator
Why do Git commit hashes use SHA-1?
Git models repositories as a directed acyclic graph (DAG) of content-addressable objects. Each commit, tree, and blob is identified by its SHA-1 hash computed over its header and data payload. Git has also introduced support for SHA-256 in modern versions.
Is it safe to generate hashes for sensitive files here?
Yes. Hash computation executes completely inside your browser using the native Web Cryptography API (crypto.subtle.digest). No text, passwords, or binary files are transmitted across the network.
What was the SHAttered attack on SHA-1?
In February 2017, researchers from CWI Amsterdam and Google announced the first real-world collision attack against SHA-1 (SHAttered), creating two different PDF documents that produced the identical SHA-1 hash. This finalized the deprecation of SHA-1 for digital signatures.
Does capitalization change the SHA-1 hash value?
Yes. SHA-1 processes raw binary bytes. In ASCII/UTF-8, uppercase 'A' is byte 0x41 while lowercase 'a' is byte 0x61, generating completely distinct hashes.