English

Developer tools · SHA hash calculator

From SHA-0 to SHA-3: How NIST's Secure Hash Standard Evolved

· Background

sha-256 cryptography browser-apis

Timeline from SHA-0 through SHA-1, SHA-2 family and SHA-3 showing two decades of evolution
Original ToolAcre vector illustration

SHA-1, SHA-2 and SHA-3 are three generations with different origins. This post traces the Secure Hash Standard from the withdrawn SHA-0 to the Keccak competition and explains why SHA-2 still dominates.

What do the numbers mean? — why SHA-256 is SHA-2 but SHA-3 is something else entirely

Developers see SHA-1, SHA-256 and SHA-3 and assume they are a linear progression. They are not. The numbers mean different things in different contexts, and understanding the family history explains why SHA-256 is the sensible choice for new applications, why SHA-1 is legacy-only despite being widely deployed, and why SHA-3 is a separate design rather than an evolution.

When NIST first published a secure hash function, they called it SHA and later SHA-0, a version so short-lived that most developers have never heard of it. The SHA-0 was withdrawn within a few years due to an unspecified flaw that was never publicly disclosed. This withdrawal happened quietly, and the algorithms that followed gave rise to the naming confusion. After SHA-0 was withdrawn, NIST published SHA-1, which became the standard for twenty years.

The tool covers SHA-1 and SHA-2; detailed SHA-0 history is outside repository evidence

SHA-1 is a 160-bit hash function that produces a 40-character hexadecimal output. It is based on the Merkle–Damgård construction, where a compression function processes input block by block, chaining the state forward. The design was sound when published, and there were no practical attacks for many years. However, the year 2005 brought a cryptanalytic breakthrough. A team led by Xiaoyun Wang published a collision attack on SHA-1, showing that finding two different messages with the same hash was feasible using techniques far more efficient than the brute force approach.

Years later, in 2017, a team called SHAttered demonstrated the first practical collision, using a cluster of GPUs to find two different PDF files with the same SHA-1 hash. In 2020, a follow-up paper showed that chosen-prefix collisions—the more dangerous variant—were affordable. SHA-1 was no longer simply weak; it was broken. The response to the SHA-1 break was to introduce SHA-2, a family of four functions: SHA-224, SHA-256, SHA-384 and SHA-512.

SHA-2 — the early-2000s family (224, 256, 384, 512 and later the truncated 512/224 and 512/256) built on the same construction

These four operate on different state sizes and different block sizes, but they use the same fundamental construction as SHA-1. The SHA-2 family was published in 2001, years before the major breaks on SHA-1, but it was not widely adopted until the SHA-1 collapses became concrete. SHA-256 produces a 256-bit hash and is now the standard choice for new applications. SHA-512 produces a 512-bit hash and is often faster on 64-bit processors because it operates on 64-bit words instead of 32-bit words.

The naming convention for SHA-2 is the source of the confusion. The functions are called SHA-256, SHA-384 and SHA-512, and they are all part of the SHA-2 family. When someone says SHA-2, they mean the design philosophy and the Merkle–Damgård construction, not a single algorithm. The numbers in the names are the output widths in bits, not a version scheme. SHA-256 is not an update to SHA-1; it is a contemporary design using the same framework but with better security properties.

The repository documents demonstrated SHA-1 collisions without reconstructing unsourced theoretical history

Inside the Merkle–Damgård construction that SHA-1 and SHA-2 use, a compression function processes input block by block. The state is carried forward from one block to the next, and the final state is output as the digest. The SHA-256 compression function uses 32-bit operations and 256-bit state, so it processes 512-bit blocks. The SHA-512 compression function uses 64-bit operations and 512-bit state, so it processes 1024-bit blocks. These choices affect the performance and the bandwidth—SHA-512 is often faster because 64-bit arithmetic is native on modern hardware.

The decision between SHA-256 and SHA-512 for a new system is usually based on performance testing and space constraints rather than security, because both are still secure as of the early 2020s. The ToolAcre SHA hash calculator provides SHA-256, SHA-384 and SHA-512, and when readers compare the digests side by side, they see the four-character difference between SHA-256 (64 hex characters) and SHA-512 (128 hex characters).

SHA-3 is outside the supported API; competition history is not asserted from repository evidence

The motivations for replacing SHA-1 were clear by the early 2000s, so NIST began the SHA-3 selection process. Rather than designing a replacement in isolation, NIST opened the competition to the cryptographic research community. The goal was to select a hash function that was fundamentally different from the Merkle–Damgård construction, to gain confidence from a diversity of designs. Multiple teams submitted proposals, and over several years, the competition selected Keccak as the winner. Keccak was a sponge construction, a different way of building a hash function that had not been used before in a standard.

SHA-3 is the NIST standardization of Keccak, finalized in 2015. Unlike SHA-2, which is a family of algorithms, SHA-3 is usually referred to as a single algorithm, though it too has multiple widths. SHA-3 is not widely deployed yet, which is striking considering it has been standard for nearly a decade. The reason is that SHA-2 is not broken. There is no pressing security reason to upgrade from SHA-2 to SHA-3. The browser's Web Crypto API implements SHA-1 and SHA-2 but not SHA-3, which is why the ToolAcre SHA hash calculator does not offer SHA-3.

SHA-2 remains the tool default; this article avoids an unsupported universal safety claim

Why SHA-2 is still everywhere is the central question of hash algorithm choice. SHA-2 has no known practical collisions. Hardware implementations are mature. Every programming language and platform supports it. Changing a system's hash algorithm is disruptive: every stored hash has to be migrated or retained for verification, every integration point has to be updated, and testing has to be performed to ensure the new algorithm works with every downstream system.

For systems where SHA-2 is still secure, this disruption is not justified. For new systems and new protocols, SHA-2 is the sensible default. The ToolAcre SHA hash calculator shows SHA-256 and SHA-512 in a prominent position because they are what new applications should use. SHA-1 is listed as legacy-only. SHA-384 is shown for completeness and for the use cases where it is specifically required.

What this does not cover — the internals of Keccak, which deserve their own post

The future of hash standards is unclear at this point in time. SHA-3 is secure and mature, and it provides an alternative if SHA-2 is ever broken. Quantum computing poses a long-term threat to all current hash functions, but quantum-resistant hash function designs are an open research area. NIST has a Post-Quantum Cryptography competition underway, selecting algorithms that are intended to resist quantum attacks, but hash functions are not a priority in that competition compared to public-key systems.

For practical applications in the 2020s, SHA-256 is the answer to the question "which hash should I use?" For integrity verification, content addressing and fingerprinting, SHA-256 is the standard. For systems that need a wider digest, SHA-512 is usually faster on 64-bit hardware. SHA-384 is most common in TLS cipher suite specifications. SHA-1 is only for legacy verification. The ToolAcre SHA hash calculator provides all four Web Crypto algorithms so developers can see their outputs.

Takeaway: three generations, one family name — the ToolAcre SHA hash calculator covers the SHA-1 and SHA-2 algorithms the browser provides

Understanding the history of SHA clarifies why the numbers and names mean what they do and why the choices made in the 1990s and 2000s still dictate what new applications do today. SHA-0 was withdrawn quietly, SHA-1 was broken by practical attacks, SHA-2 is still secure, and SHA-3 is an alternative design chosen for future robustness. New code should use SHA-256 for general-purpose hashing. Legacy systems still use SHA-1, and interoperability with those systems requires the ability to compute SHA-1 hashes.

The ToolAcre SHA hash calculator embodies this perspective: it offers SHA-256 as the default, SHA-512 as a wider option, SHA-384 for specific requirements, and SHA-1 labeled as legacy. This provides developers with accurate tools and accurate labeling. The browser's Web Crypto implementation provides these algorithms, and ToolAcre uses that implementation directly rather than shipping custom code. The choice reflects decades of cryptographic evolution and the current state of practice.