Compare checksums
Compare a local file hash with the SHA-256 value published in release notes or download pages.
브라우저 내부 처리
Calculate SHA hashes for uploaded files locally in the browser.
Comparing hashes is the reliable way to confirm a build artefact or received file was not corrupted in transit. Check the value computed here against the published checksum. The whole file is read in the browser and never uploaded, which makes it usable for internal files too.
Compare a local file hash with the SHA-256 value published in release notes or download pages.
The browser reads the file and computes the hash locally; the selected file is not uploaded by this tool.
When needed, keep SHA-256 and SHA-512 values together in verification notes.
Hex digests are case insensitive. 9B2E and 9b2e are the same value — normalize the case before comparing.
Hashing happens in memory, so multi-gigabyte files can overwhelm the tab. Use an OS command such as shasum or certutil for those.
SHA-1 has demonstrated collision attacks and is unsuitable for security verification. Use SHA-256 or stronger.
A hash identifies file content and helps with integrity checks. It does not restore the original file or provide secrecy.
Very large files can use more browser memory and processing time. Wait briefly before assuming the calculation failed.
Matching hashes effectively mean identical files, but a slightly corrupted download produces a completely different hash. So a hash cannot tell you how much changed — that is a diff tool's job.
The hash is computed in your browser, so the whole file must be read. Multi-gigabyte files can be slow or hit memory limits. In exchange nothing is uploaded, which is what makes it safe for internal files.
Collisions in SHA-1 can be constructed deliberately, so it is unsuitable for signatures or security verification. It is still fine for checking whether a transfer corrupted a file. Use SHA-256 or stronger where security matters.
Input
ubuntu-24.04.iso
Output
SHA-256
9b2e1f...c47a3d
If a single character differs from the published checksum, the file is corrupted or tampered with.