SHA-256 and SHA-512: how to check that a file has not changed
A hash is a fingerprint calculated from the contents of a file. If the file changes, the value changes. That lets you compare copies without opening them or checking them byte by byte.
What exactly is a hash
SHA-256 and SHA-512 belong to the SHA-2 family defined by NIST. They accept any amount of data and produce a fixed-size output: 256 bits for SHA-256 and 512 bits for SHA-512. The result is usually displayed as a hexadecimal string. It does not contain the file or allow it to be reconstructed; it is a reproducible summary of its contents.
What it means when two hashes match
If you calculate SHA-256 for a downloaded file and the result exactly matches the value published by a trusted source, you can verify that the received content matches the content for which that hash was published. A tiny change in the file produces, with overwhelming probability, a different result. The filename does not matter: you can rename it and the hash remains the same as long as the contents do not change.
A hash confirms integrity, not reputation. If you compare a file with a hash obtained from an untrusted source, a match only proves that both refer to the same content.
SHA-256 or SHA-512
For file-integrity checks, SHA-256 is widely used and sufficient in the great majority of cases. SHA-512 produces a longer digest and is also part of the SHA-2 standard. The practical choice usually depends on the value published by the source you want to compare against. The important point is to use the same algorithm on both sides.
When checking a hash is useful
- After downloading software or a system image when the provider publishes a SHA-256 or SHA-512 value.
- To check whether two copies of a file are identical even if they have different names.
- To verify a backup after moving or storing it.
- Before and after an important transfer when you need to confirm that the content did not change.
Do not use SHA-256 to store passwords
SHA-256 and SHA-512 are fast functions, which is useful for file verification but a poor property for password storage. Passwords use functions designed to slow down and increase the cost of large-scale guessing, such as Argon2id, scrypt or PBKDF2 depending on the environment. The Rusadix hash generator is intended for files and integrity, not for building a password-storage system.