The domain sha3.si is for sale. Make an offer or buy it now →

SHA-3 vs SHA-256

Both are secure, standardised and widely supported. They differ in design, not in strength, and that difference is the whole point.

SHA-256 (SHA-2)SHA3-256 (SHA-3)
StandardFIPS 180-4FIPS 202
Published20012015
DesignMerkle-Damgard with a Davies-Meyer compression functionSponge construction on the Keccak-f[1600] permutation
Output256 bits256 bits
Collision resistance128 bits128 bits
Length-extension attackVulnerable when misused as a MAC (use HMAC)Not vulnerable
Variable-length outputNoYes, via SHAKE128 / SHAKE256
Software speedUsually faster, with dedicated CPU instructionsUsually slower in software, fast in hardware
Typical useTLS, Bitcoin, code signing, general hashingPost-quantum standards, protocols that need an XOF, design diversity

Same input, unrelated outputs

"hello world" through each function:

FunctionDigest (hex)
SHA-256b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9
SHA3-256644bcc7e564373040999aac89e7622f3ca71fba1d972fd94a31c3bfbf24e3938
Keccak-25647173285a8d7341e5e972fc677286384f802f8ef42a5ec5f03bbfa254cb01fad

Which should you use?

Frequently asked

Is SHA-3 more secure than SHA-256?

Both are considered secure with no practical attacks. SHA3-256 and SHA-256 give the same 128-bit collision resistance. SHA-3 has a different design and is immune to length-extension attacks.

Is SHA-3 faster than SHA-256?

In software on common CPUs, SHA-256 is usually faster, especially with SHA hardware instructions. SHA-3 is very efficient in hardware.

Should I switch from SHA-256 to SHA-3?

Not for security reasons alone. Choose SHA-3 when a standard or protocol requires it, when you need an XOF (SHAKE), or when you want design diversity.

Own sha3.si

A short, exact-match domain for one of the world's core cryptographic standards. Ideal for a security, cryptography, blockchain or developer-tools brand.

Buy now or make an offer Why this name