TinyFileLab

Home›Developer›Hash generator

Files are read in the page — nothing is uploaded

Hash generator

Five digests at once, for text you type or a file you drop. The file never leaves your machine, which is the only sensible way to verify a download you have not run yet.

Text hashed as you type, UTF-8
Or hash a file drop it here, or tap to choose — nothing is uploaded

MD5 is computed in this page; the SHA family comes from the browser's own Web Crypto implementation.

Compare paste a published checksum to check it

All five digests are checked at once, so you need not know which one it is.

Nothing is transmittedThe page does the work locally. No request carries your data anywhere.
No length limitPaste as much as you like — the only ceiling is your own memory.
No account, no ads in the wayOpen the page, use it, close it. Nothing to sign up for.

Five algorithms, one input

A hash function turns any input into a fixed-length fingerprint. Change one bit of the input and roughly half the output bits flip — which is what makes hashes useful for detecting corruption, deduplicating files, and confirming that the installer you downloaded is the one the publisher built. This page computes MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at the same time, because when you are checking a value against a published one you rarely know in advance which algorithm it came from.

The comparison box at the bottom exists for exactly that: paste the checksum from a release page and it tells you which of the five it matches, or that it matches none of them. That is quicker and less error-prone than reading two 64-character hex strings side by side, which is a task human eyes are genuinely bad at.

Where each digest comes from

The SHA family is computed by crypto.subtle.digest — the browser's own Web Crypto implementation, which is native code, constant-time and considerably faster than anything JavaScript could do. Web Crypto deliberately does not offer MD5, on the reasonable grounds that it should not be used for anything security-related, so MD5 here is implemented in the page and verified against the RFC 1321 test vectors.

One consequence worth knowing: Web Crypto is only exposed in a secure context. Over https it works; opening a page from a file:// URL in some browsers, it does not, and only MD5 would appear. The status line will tell you if that happens.

MD5 and SHA-1 are broken, and still everywhere

Both are cryptographically dead. Practical MD5 collisions have been generated since 2004, and SHA-1 fell in 2017 when researchers produced two different PDFs with the same digest — a full collision, on real hardware, for a realistic budget. Neither should be used for signatures, certificates, password storage or anything else where an adversary gets to choose the input.

They remain useful for the non-adversarial half of the job. Verifying that a 4 GB file survived a transfer intact, spotting duplicate files, or checking a value against a legacy system's stored digest are all fine — nobody is attacking your file copy. That is why both are still published alongside SHA-256 on plenty of download pages, and why they are still on this page.

Hashing a file is not the same as encrypting it

Hashes are one-way. There is no operation that turns a digest back into the file. The "hash decrypter" sites that claim otherwise are running dictionary lookups: they have precomputed the hashes of billions of common passwords and are searching that table. It works for password123 and fails completely for anything with real entropy — which is the argument for salted, deliberately slow password hashes like bcrypt or Argon2, and against ever putting a plain SHA-256 in a password column.

Why doing it locally matters here

The most common reason to hash a file is to check an installer or an archive you have just downloaded and do not yet trust. Uploading that file to a website to have it hashed is a strange move — you have handed a stranger a copy of something before establishing what it is, and on a slow connection you have waited a long time to do it. Here the file is read with the browser's file API, hashed in memory and never transmitted; a multi-gigabyte file is limited by your memory and your patience, not by an upload allowance. If you need identifiers rather than digests, the UUID generator is next door.

Common questions

Which hash should I use?

SHA-256 for anything new. MD5 and SHA-1 are fine for detecting accidental corruption but are cryptographically broken, so never use them where someone could deliberately craft a colliding input.

Can a hash be reversed?

No. Hashing is one-way by construction. Sites advertising hash 'decryption' are looking values up in precomputed tables of common passwords, which only works when the input was guessable.

Why is MD5 not in Web Crypto?

Because the specification deliberately excludes algorithms considered unsafe. MD5 on this page is implemented in JavaScript and checked against the official RFC 1321 test vectors.

Is my file uploaded to be hashed?

No. It is read into memory by your browser and hashed there. That is the point — you would not normally want to send a file you have not yet verified to anyone.

How large a file can I hash?

As large as your browser can hold in memory. There is no server-side limit because there is no server; several gigabytes is realistic on a desktop machine.

Why do two files with the same name give different hashes?

Because the hash covers the bytes, not the name or the metadata. Re-saving, re-encoding, or even a different line ending changes the digest completely.

What does the compare box check?

It matches the value you paste against all five digests at once and tells you which one it was, so you do not need to know which algorithm the publisher used.