“Just MD5 it, it's only a checksum.” Six months later that checksum guarded password resets. Hash choice is a security decision wearing a utility costume: MD5 for legacy manifests, SHA-256 for integrity, bcrypt for passwords — and the wrong pick fails silently for years. This guide gives digest lengths that identify algorithms on sight, the avalanche intuition, and the hash-vs-HMAC-vs-encryption ladder, with hello worked through every level.
Part of the developer toolkit guide. Compare in the hash generator; step up keyed hashing in HMAC; encrypt secrets with AES.
Digest lengths identify algorithms on sight
| Algorithm | Hex length | hello starts | Use for |
|---|---|---|---|
| MD5 | 32 | 5d41402a… | Legacy checks only |
| SHA-1 | 40 | aaf4c61d… | Legacy (git internals) |
| SHA-256 | 64 | 2cf24dba… | Integrity, fingerprints |
| SHA-512 | 128 | 9b71d224… | High-assurance digests |
Count the hex: 32/40/64/128 tells you the algorithm before any label does. Case varies by tool (uppercase manifests vs lowercase APIs) — normalize before comparing, and compare full strings, never prefixes.
Avalanche: hello vs hallo rewrites everything
Flip one letter and the digest scrambles completely — hello and hallo share no recognizable prefix. That avalanche is the security property: no partial credit for close guesses. It also kills two folk practices: leet substitutions (a→4) barely change crack time because attackers normalize them, and truncated digests (“first 8 chars match!”) prove nothing. Test both inputs side by side in the hash generator to build the intuition permanently.
The ladder: hash vs HMAC vs AES (when to climb)
- Hash (SHA-256): fingerprinting downloads, cache keys, dedupe. Anyone can recompute — proves integrity against accidents, not attackers.
- HMAC: hash plus secret key — proves the message came from a key holder. Webhooks, API signatures. Step up in the HMAC tool.
- AES encryption: reversible secrecy for stored/transmitted data. Passwords get bcrypt/argon2 instead (slow by design). Encrypt in the AES tool.
Passwords are the classic misplacement: fast hashes (even SHA-256) fall to GPUs in hours; password hashing must be slow (bcrypt cost factors) plus salted per user. If your login table uses MD5/SHA, migrating to argon2 outranks every feature on the roadmap.
General guidance only, not a security audit. Hash choices for regulated data need professional review — this page builds intuition, not compliance.