๐Ÿ” Hash Converter & Verifier

Algorithm details & security notes

SHA-256 / SHA-512 โ€” Modern hash functions from the SHA-2 family. Used for integrity verification and digital signatures. NOT suitable for password storage (too fast โ€” GPUs can compute billions per second).

SHA-1 โ€” Cryptographically broken since 2017 (SHAttered attack). Use only for legacy compatibility (e.g., old Git objects, X.509 certs).

MD5 โ€” Broken since 2004 (collisions found). Use ONLY for checksums and legacy integration. Never for security. This implementation matches RFC 1321.

bcrypt โ€” Adaptive password hash based on Blowfish. Resistant to GPU/ASIC attacks due to memory-hard access pattern. The cost factor doubles compute time per increment. Real bcrypt produces hashes starting with $2a$, $2b$, or $2y$.

PBKDF2 โ€” Password-Based Key Derivation Function 2 (RFC 2898). Simple iterative HMAC. OWASP recommends โ‰ฅ 600,000 iterations with SHA-256 as of 2023. Output is in Django-compatible format: pbkdf2_sha256$iterations$salt$hash.