Algorithms

SHA-1

A 160-bit hash broken by SHAttered in 2017. Still inside Git and old systems and it has HMAC
IDsha118 / 24legacy · 160-bit
Hash / Legacy

SHA-1

Broken since SHAttered, still inside Git.

Digest
160-bit · 20 bytes
HMAC
takes a key
Security
BROKEN: practical collision attack (SHAttered)
Family
2 in legacy
2 options, 0 required

Sample

hex
2aae6c35c94fcfb415dbe95f408b9ce91ee846ed
base64
Kq5sNclPz7QV2+lfQIuc6R7oRu0=

Options

encodingstring
default hex
Output encoding: hex, base64, base64url, binary
keystring
optional
HMAC key; enables HMAC mode

Access

Createcreate("sha1")
CLIhashes sha1 'hello world'
Tryplayground with the sample above
Kinmd5

Broken in practice since SHAttered in 2017, two different PDFs with one SHA-1. Git still names objects with it (with a collision detector bolted on), and plenty of old protocols still speak it.

ts
create("sha1").hash("abc").digest; // "a9993e364706816aba3e25717850c26c9cd0d89d"
create("sha1").hash("").digest; // "da39a3ee5e6b4b0d3255bfef95601890afd80709"

For compatibility, fine. For anything new, SHA-256. HMAC-SHA1 still holds up as a MAC, which is why TOTP apps still use it.