Understanding SHA-256
A SHA-256 hash is a 64-character fingerprint of a file. This guide explains how it works, what it proves, and why you should verify it before running any download.
What a Hash Function Does
A cryptographic hash function takes any input — a file, a password, a string of text — and produces a fixed-length output called a hash. The same input always produces the same hash. Change one byte of the input, and the output changes completely.
SHA-256 is one specific hash function in the SHA-2 family, standardized by the US National Security Agency and published by NIST. It produces 256 bits of output, which is typically written as 64 hexadecimal characters.
Why It Matters for Downloads
When a publisher lists a SHA-256 hash for a file, they are saying: "The file you should have downloaded, when you compute its hash, will produce exactly this string."
If your file's hash matches the published hash, the file is byte-for-byte identical to the one the publisher verified. If even one byte differs — a modified executable, an injected script, a corrupted transfer — the hash will be completely different.
What SHA-256 Proves
- Integrity: The file was not corrupted during download.
- Source identity: The file matches the exact build the publisher verified.
- Tamper detection: Any modification — even a single character — is detectable.
What SHA-256 Does Not Prove
- Safety: A matching hash means the file is identical to the verified version. It does not mean the file is free of malware.
- Intent: It does not prove the file does what it claims.
- Legality: It does not mean the distribution is authorized.
This is why we say in our Safety Center: a matching SHA-256 confirms integrity, not safety.
How a Hash Is Computed
Hashing is deterministic. The algorithm reads the file in blocks, mixes the data with mathematical operations, and produces the final hash. Any tool that implements SHA-256 correctly will produce the same result — a hash computed by PowerShell, CertUtil, or an online service will all match if the file is the same.
Why SHA-256 Instead of SHA-1 or MD5
- MD5: Broken. Collisions (two different inputs producing the same hash) can be generated in seconds. Never use MD5 to verify downloads.
- SHA-1: Deprecated. Practical collision attacks exist. Do not rely on SHA-1.
- SHA-256: No known practical attacks. Recommended for file verification.
How to Verify a Hash
See our step-by-step guide: How to Verify SHA-256 on Windows. The short version: open PowerShell, run Get-FileHash "path\to\file" -Algorithm SHA256, and compare the output to the published hash.
Common Mistakes
- Comparing only the first and last few characters — always compare the full 64-character string.
- Downloading from a mirror and assuming the hash will match. If the mirror served a different file, it won't.
- Trusting a hash published on the same compromised site that served the file. If the site is compromised, both can be changed together.
- Assuming SHA-256 is case-sensitive. It is not.
a3f5andA3F5refer to the same hash.