sha-256 checksum
hash any text or local file with sha-256 using your browser's native crypto engine. the classic use: compare a downloaded file (tor browser, tails image...) against the checksum its publisher announced - one different character means a tampered file.
verify like a pro
- download the file from the official source.
- find the official sha-256 checksum on the same site - the tor project lists it per download ("checksum" / sig details), tails publishes a signed checksum next to each usb image. even better: a checksum inside their pgp-signed release notes.
- hash the file here and compare character by character (all 64) - or paste both hashes into our text diff and let it spot the difference for you.
- match? you hold exactly the bytes the publisher signed off. mismatch? do not open it.
faq
- are my files uploaded?
- no. hashing happens with the browser's built-in crypto engine on your device. even multi-gigabyte files never leave your computer.
- is sha-256 still safe?
- yes. there is no known practical way to craft two different files with the same sha-256 hash. it is the standard for download verification everywhere.
- the publisher only lists md5 / sha1 - now what?
- those are broken for security purposes. treat md5-only releases as a bad sign and prefer sources that publish sha-256.