Algorithms

SHA-0

The 1993 original of SHA-1. Withdrawn within two years and fully collided in 2004. Here for old papers and puzzles and it has HMAC
IDsha019 / 25SHA · 160-bit
Hash / Legacy

SHA-0

SHA-1 minus one rotation, replaced in 1995.

Digest
160-bit · 20 bytes
HMAC
takes a key
Security
BROKEN: full collision found in 2004
Family
9 in SHA
2 options, 0 required

Sample

hex
9fce82c34887c1953b40b3a2883e18850c4fa8a6
base64
n86Cw0iHwZU7QLOiiD4YhQxPqKY=

Options

encodingstring
default hex
Output encoding: hex, base64, base64url, binary
keystring
optional
HMAC key; enables HMAC mode

Access

Createcreate("sha0")
CLIhashes sha0 'hello world'
Tryplayground with the sample above
Kinsha256, sha384, sha512, sha512-half +4

SHA-1 before the fix. FIPS 180 published it in 1993, the NSA withdrew it soon after without naming the flaw, and SHA-1 arrived in 1995 with exactly one change: a one-bit rotation in the message schedule. Same constants, same eighty steps, completely different digests.

That bit mattered. Chabaud and Joux described a collision attack in 1998, a full collision followed in 2004, and in 2005 Wang, Yin and Yu cut the cost to about 2^39 operations.

ts
create("sha0").hash("abc").digest; // "0164b8a914cd2a5e74c4f7ff082c4d97f1edf880"
create("sha0").hash("").digest; // "f96cea198ad1dd5617ac084a3d92c6107708c0ef"

Node's OpenSSL doesn't have it and neither does Python's hashlib, which is exactly why a puzzle author reaches for it. Here it's for the exercise sheet, the 1998 paper and that puzzle. For anything real, SHA-256.