GhostXStudio tools

What is a SHA-256 checksum, and what does it prove?

Updated

Short answer

A SHA-256 checksum is a 64-character fingerprint computed from every byte of a file. If two files have the same SHA-256, they are, for all practical purposes, identical; change a single bit and the fingerprint changes completely. It proves a file is unchanged, not who made it or whether it’s safe.

How a hash works

SHA-256 is a cryptographic hash function from the SHA-2 family, specified by NIST in FIPS 180-4. It reads any amount of data and produces a 256-bit result, usually written as 64 hexadecimal characters. Three properties make it useful:

  • Deterministic: the same bytes always produce the same hash, on any computer.
  • Sensitive: changing one bit of the input changes roughly half the bits of the output, so similar files have completely different hashes.
  • One-way and collision-resistant: you can’t work back from a hash to the file, and no one has found two different inputs with the same SHA-256.

What a matching hash proves

If the SHA-256 of your file matches a published or recorded value, your file is byte-for-byte the file that value was computed from. That is how you confirm a download wasn’t corrupted or swapped, that a backup matches the original, or that a document is the exact version described in a certificate.

A match says nothing about who created the file, whether it is safe to open, or whether its content is true. And it is only as trustworthy as the source of the reference hash: if an attacker can replace both a download and the checksum printed next to it, both will match. Get the reference hash through a separate, trusted channel, or rely on a digital signature, which binds a hash to a key.

What changes a hash — and what doesn’t

The hash covers the file’s contents only. Renaming a file, moving it, or changing its file-system dates doesn’t change the hash. Anything that alters the bytes does: re-saving a document, editing embedded metadata, a messaging app recompressing a photo, or a PDF tool ‘optimizing’ a file. Two files that look identical on screen can have different hashes because of such hidden differences.

SHA-256 versus MD5 and SHA-1

MD5 and SHA-1 are older hash functions for which practical collision attacks exist — people can deliberately create two different files with the same hash. They are still fine for catching accidental corruption, but for anything where someone might tamper with a file, use SHA-256 or stronger.

How to compute a SHA-256 checksum

  • Windows (PowerShell): Get-FileHash file.pdf — SHA-256 is the default algorithm. In Command Prompt: certutil -hashfile file.pdf SHA256.
  • macOS: shasum -a 256 file.pdf in Terminal.
  • Linux: sha256sum file.pdf.
  • In a browser: GhostX’s ‘Check it’s unchanged’ tool computes the SHA-256 of a file on your device.

When comparing, hexadecimal case doesn’t matter (A and a are the same digit). Compare the whole string, not just the first and last few characters.

Where file fingerprints are used

  • Software downloads, where publishers list checksums for each file.
  • Evidence and records, where a hash recorded at collection time shows a file hasn’t changed since.
  • Digital signatures, which sign a document’s hash rather than the document itself.
  • Timestamps, which prove a file existed at a point in time by submitting only its hash — so the timestamping service never sees the file.
  • Audit certificates: GhostSign’s signature certificate records the SHA-256 of the original and the signed document, and GhostX’s redaction certificate records the hashes of the source and the redacted output.

Checking a file with GhostX

GhostX’s ‘Check it’s unchanged’ tool computes a file’s SHA-256 in your browser, for files up to 500 MB, and lets you copy it or pick a second file to compare the two. The /verify page also shows the SHA-256 of any file you drop on it. The file isn’t uploaded for either.

Frequently asked questions

  • Can two different files have the same SHA-256?

    In theory yes, because there are more possible files than hashes, but no collision has ever been found for SHA-256 and finding one is considered computationally infeasible.

  • Is a hash the same as encryption?

    No. Encryption is reversible with a key; a hash is one-way. You can’t recover a file from its SHA-256.

  • Does renaming a file change its checksum?

    No. The name isn’t part of the file’s contents. Editing the file, including its embedded metadata, does change it.

  • Why doesn’t my downloaded file’s checksum match?

    The download may be incomplete or corrupted, you may have a different version than the one listed, or the file may have been altered. Download it again from the official source and re-check.

References