About the SHA-1 Hash
SHA-1 (FIPS 180-4) outputs 160 bits, shown as 40 hex characters; for example sha1("abc") = a9993e364706816aba3e25717850c26c9cd0d89d. It is computed here with the browser's native crypto.subtle.digest('SHA-1', …), on the UTF-8 bytes of your text or the raw bytes of a chosen file.
SHA-1 is no longer collision resistant. In 2017 the SHAttered attack produced two different PDFs with the same SHA-1, and in 2020 chosen-prefix collisions became practical. Browsers stopped trusting SHA-1 TLS certificates in 2017. Do not use it for new signatures; SHA-256 is the usual replacement.
You will still meet SHA-1 in legacy systems: Git object IDs (Git is migrating to SHA-256 and detects the known collision technique), older HMAC-SHA1 APIs and TOTP authenticator codes, where HMAC's construction keeps it safe for now. Note that a Git blob ID hashes a blob <size>\0 header plus the content, so it differs from the plain SHA-1 of the file.
How to use it
- Enter text or choose “Hash a file”.
- Read the SHA-1 digest at the top.
- Pick hex, upper-case hex or Base64 output.
- Copy the value.