Security

SHA-256, SHA-384, SHA-512: hash algorithms explained without maths

A hash is a short fingerprint of a file: change one character and the fingerprint changes completely. SHA-256, 384 and 512 are three fingerprint sizes. Automatic picks the right one for your key, and that is the setting almost everyone should leave alone.

4 min read

Under Advanced in the Digital Signature tool there is one setting: "Hash algorithm", offering *Automatic (recommended)*, SHA-256, SHA-384 and SHA-512. Here is what it means, with no mathematics.

What a hash actually is

Feed a file (any file, any size) into a hash function, and out comes a short string of characters. Always the same length. Always the same result for the same file.

Three properties make it useful:

  1. The same file always gives the same fingerprint.
  2. Any change gives a completely different one. Change a full stop to a comma and the fingerprint is unrecognisable, not slightly different, entirely different.
  3. You cannot work backwards. The fingerprint tells you nothing about the file's contents.

The everyday version

Imagine a machine that reads a book and produces a six-word summary.

  • The same book always produces the same six words.
  • Change one word anywhere in the book and the six words come out completely different.
  • Nobody can rebuild the book from the six words.

Now you can prove two people have the same book without either of them sending it.

What this has to do with signing

Signing a whole document would be slow and clumsy. So signing software does this instead:

  1. Take the fingerprint of the document.
  2. Lock that fingerprint with your private key.

Checking later is the mirror image: take the fingerprint of the document as it is now, unlock the one stored in the signature, compare. Identical means nothing has changed. Different means something has, and that is exactly what a PDF reader is doing when it tells you a document was modified after signing.

It is the same trick behind the trusted timestamp: only a fingerprint is sent to the timestamp service, never the document.

So what do 256, 384 and 512 mean?

The length of the fingerprint, in bits. SHA-256 produces a 256-bit fingerprint, SHA-512 a 512-bit one.

Longer means more possible fingerprints, which means it is even harder for two different documents to end up sharing one. But "harder" is doing very little work in that sentence:

  • SHA-256 is accepted everywhere, used by banks and governments worldwide, and there is no practical way to break it.
  • SHA-384 and SHA-512 are longer still. Not *meaningfully* safer for ordinary documents, because 256 is already far beyond reach.

The honest summary: SHA-256 is not the weak option. It is the standard one.

Why "Automatic" is the right answer

Automatic uses SHA-256, unless your certificate uses an ECDSA P-384 or P-521 key, in which case it uses SHA-384 or SHA-512, the fingerprint length that matches that key's strength.

That is the whole rule. Picking a longer hash than your key needs adds nothing; picking a shorter one than it expects can cause trouble.

When you would change it

Only one situation: your organisation told you to. Some institutions specify a hash in writing, usually because a standard they follow names one. If you have been given that instruction, choose the one you were told to use.

Otherwise leave it on Automatic. The tool's own hint puts it the same way: *"Choose one yourself only if your organisation requires it."*

One thing to watch with tokens

If you sign with a USB token or smart card, the device itself may support only certain hashes. Choose one it does not know and you will see: *"Your token cannot sign with this hash algorithm. Choose Automatic under Advanced."*

Do exactly that.

Where to see which was used

After signing, the result line shows the hash beside the signature's profile. In Verify PDF Signature, each signature lists its hash algorithm next to the signing time.

What a hash is not

  • It is not encryption. Encrypted things can be decrypted; a hash cannot be reversed at all.
  • It is not a password. It is a check value, not a secret.
  • It is not a signature. A signature is a hash locked with a private key: the key is what ties it to you.

Common questions

What is a hash algorithm in a digital signature?

It is the method used to make a short fingerprint of the document. The signature locks that fingerprint, so any later change to the file makes the fingerprints disagree.

Which hash algorithm should I choose for signing a PDF?

Automatic. It uses SHA-256, which is accepted everywhere, and switches to SHA-384 or SHA-512 when your key needs a matching length.

Is SHA-512 more secure than SHA-256?

It produces a longer fingerprint, but SHA-256 is already far beyond any practical attack. For ordinary documents the difference has no real effect.

Is SHA-256 still safe?

Yes. It is the standard choice for document signing worldwide and there is no known practical way to break it.

My token refused the hash I chose. What do I do?

Set Hash algorithm back to Automatic under Advanced. Some tokens support only specific hashes, and Automatic picks one the device accepts.

Can a hash be turned back into the document?

No. It is a one-way fingerprint. That is why sending one to a timestamp service does not reveal what you signed.