SHA-256
In short: A widely used hashing algorithm from the SHA-2 family that produces a 256-bit (32-byte) hash value from arbitrary input data.
In more detail: SHA-256 stands for “Secure Hash Algorithm, 256 bit” and is currently considered cryptographically secure (unlike the outdated SHA-1). Typical uses: integrity checking of downloads (checksums), password hashing (usually combined with a salt), certificates and digital signatures, and blockchain systems like Bitcoin. The number in the name gives the length of the output value — SHA-512 accordingly produces a 512-bit hash.
In Depth
Fixed output length, no matter how large the input
SHA-256 always produces exactly 256 bits for any input (whether 1 byte or several gigabytes), shown as 64 hexadecimal characters:
$ echo -n "" | sha256sum
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
$ echo -n "Emzett" | sha256sum
a1f7d3c2... (example — even the tiniest input results in a fixed 256-bit hash)Even the hash of the empty string (above) is a fixed, world-wide identical value — anyone applying SHA-256 to nothing gets exactly the same 64-character hex value, which in practice serves as a kind of “fingerprint of the empty input” used as a reference value in many systems.
Practical uses
In practice SHA-256 is used in very different contexts: when downloading large files, a SHA-256 hash is often published so you can check after downloading whether the file arrived intact and unchanged (sha256sum -c checksums.txt). Git long used SHA-1 for commit hashes and is gradually migrating to SHA-256, because SHA-1 is considered susceptible to collisions (see the SHAttered collision, see Hashing). Bitcoin uses SHA-256 twice in a row (SHA-256d) as the core of its proof-of-work mining algorithm — miners have to find, through massive trial and error, an input value whose hash starts with a certain number of leading zeros, which is practically solvable only through raw computing power (not cleverness), which is what secures the consensus mechanism.
Internal workings (simplified)
SHA-256 processes the input in 512-bit blocks via a so-called Merkle-Damgård construction: the message is split into blocks (with defined padding at the end, so the total length is always a multiple of 512 bits), and each block goes through 64 compression rounds that gradually mix the internal 256-bit state with the message data — bitwise rotations, XOR operations and modular additions ensure that changes anywhere in the input end up spreading across the entire output value (avalanche effect). The final internal state after the last block is the output hash.
Difference from encryption
An important difference from encryption: SHA-256 itself is NOT used to encrypt passwords, but to hash them — real login systems, however, usually don’t use SHA-256 directly, but deliberately slower algorithms optimised for passwords, like bcrypt or Argon2 (see Hashing for details on why speed is a disadvantage here). An attacker with specialised hardware can compute SHA-256 billions of times per second — for checksums that’s an advantage (fast verification), for password hashing it’s a security problem, which is why deliberately slower methods are chosen there.
The avalanche effect in practice
A particularly illustrative feature of SHA-256 is the avalanche effect already mentioned: even the smallest possible change to the input (a single flipped bit) leads to a completely different, unpredictable hash output — there are no “similar” hashes for “similar” inputs. This is easy to observe yourself:
$ echo -n "Emzett" | sha256sum
# gives hash A
$ echo -n "emzett" | sha256sum
# gives hash B - completely different, even though only ONE letter (case) was changedThis property is essential for security: if there were a correlation between similar inputs and similar hashes, an attacker could search systematically for a matching input instead of having to guess completely at random — the avalanche effect prevents exactly that and forces an attacker to try every possible input essentially independently.