Frequently Asked Questions
Answers to common questions about Crypto & Hash Tools: how the tools work, how privacy is handled, what hashing is, how HMAC differs from a plain hash, what CRC32 is used for, how UUIDs behave, and how the regex utilities fit together. All processing happens locally in your browser.
Questions and Answers
- What is the purpose of this website?
- Crypto & Hash Tools provides free, browser-based cryptographic and regex utilities for developers, security professionals, and anyone needing hash generation, HMAC creation, checksum validation, UUID generation, or regex testing. All tools run locally in your browser for maximum privacy.
- Is this service really free?
- Yes, all tools are completely free to use with no limitations. Voluntary donations help keep the service free.
- Is my input uploaded to a server?
- No. Every tool runs as browser JavaScript. The text you enter is hashed, signed, or matched on your device and is never transmitted over the network.
- What is local processing?
- Local processing means all computations happen in your web browser using JavaScript. When you generate a hash or test a regex pattern, the calculation is performed on your device, not on a server.
- Can I use these tools offline?
- Once a page is loaded, most tools continue to work offline because the computation happens in your browser. An internet connection is only needed to load the page initially.
- Do the tools set cookies or track me?
- The tools themselves do not set cookies and do not use analytics to track your calculations. Standard web infrastructure may log basic access requests, as described in the privacy policy.
- What is hashing?
- Hashing is a one-way cryptographic function that converts data into a fixed-length digest. It is used for integrity verification, digital signatures, and content fingerprinting. It is not the same as encryption.
- What is the difference between hashing and encryption?
- Hashing is one-way and cannot be reversed; encryption is two-way and needs a key to decrypt. Use a hash when you only need to verify or fingerprint data, and encryption when you need to recover the original data later.
- What is MD5 and is it still safe?
- MD5 produces a 128-bit digest. It is cryptographically broken for collision resistance — practical collision attacks exist — so it should not be used for signatures, certificates, or password storage. It remains acceptable only for non-adversarial integrity checks and legacy compatibility.
- Why is SHA-1 deprecated?
- Practical collision attacks, most famously the 2017 SHAttered attack, showed that two different inputs can produce the same SHA-1 hash. SHA-1 should not be used for new security designs; SHA-256 is the recommended replacement.
- What is SHA-256 used for?
- SHA-256 is the modern standard for integrity verification, digital signatures, certificate signing, and content-addressed storage. It produces a 256-bit digest and has no known practical collision attack.
- What is the difference between SHA-256, SHA-384, and SHA-512?
- All three are SHA-2 functions. SHA-256 produces a 64-character hex digest; SHA-512 produces a 128-character digest; SHA-384 is a truncated variant of SHA-512 producing a 96-character digest. SHA-256 is sufficient for most uses; the longer variants offer a larger security margin.
- Can I use SHA-256 or SHA-512 for passwords?
- Not by themselves. They are fast and unsalted, so a stolen database of hashes can be brute-forced quickly. Use a dedicated password hash such as bcrypt, scrypt, or Argon2, which add a salt and a configurable work factor.
- What is HMAC?
- HMAC (Hash-based Message Authentication Code) combines a hash function with a secret key to verify both data integrity and authenticity. It is commonly used in API authentication and webhook signing. It provides authentication, not encryption.
- How is HMAC different from a plain hash?
- A plain hash proves only integrity — that the data has not changed. An HMAC adds a secret key, so it also proves authenticity — that the tag was produced by someone who knows the key.
- Does HMAC encrypt my message?
- No. HMAC provides integrity and authentication, not confidentiality. The message remains in plain text. If you need confidentiality, use encryption in addition to HMAC.
- What is CRC32 used for?
- CRC32 is a checksum used to detect accidental changes to data, common in file compression, network protocols, and data transmission. It is not a cryptographic hash and must not be used for security.
- Is CRC32 a cryptographic hash?
- No. CRC32 is a checksum for detecting accidental errors. Collisions are trivial to produce, so it must not be used to detect deliberate tampering, for authentication, or for passwords.
- What is a UUID?
- A UUID (Universally Unique Identifier) is a 128-bit identifier standardized by RFC 4122, written as 32 hexadecimal digits in five groups. Version 4 UUIDs use random bits to make collisions practically impossible without coordination.
- Can I use a UUID as a password or secret token?
- A UUID is an identifier, not a secret. If you need an unguessable token, use a purpose-built generator with sufficient entropy.
- Does a valid UUID mean the identifier exists?
- No. UUID validation confirms format only. It does not confirm that the UUID refers to a real record in any system, and it is not a security control.
- How do the regex tools differ?
- The Regex Tester runs a pattern against text with live highlighting. The Regex Explainer breaks a pattern into tokens and describes each. The Regex Generator provides ready-made patterns for common validations. The Regex Cheat Sheet is a searchable syntax reference.
- What is ReDoS?
- Regular Expression Denial of Service happens when a pattern with nested or overlapping quantifiers causes catastrophic backtracking on certain input, hanging the engine. Avoid ambiguous nested repetition and test patterns on realistic input.
- Is regex a substitute for a parser?
- No. Regex is well suited to matching and extracting text, but it is not appropriate for nested structures such as HTML or complex file formats. Use a proper parser for those cases.
- Are these tools secure for sensitive data?
- Because all processing happens in your browser and no data is transmitted to servers, the tools are suitable for sensitive values such as API keys and tokens. Always follow your organization's security policies as well.
- What are the limitations of client-side tools?
- The tools depend on your browser's JavaScript engine and the underlying libraries. They compute correct values but do not make a design secure on their own — algorithm choice, key management, and operational practices remain your responsibility. For critical work, verify against an independent implementation.