Practical guide and verification
Know what SHA-1 can still prove
SHA-1 can still be useful as a quick accidental-change fingerprint when a legacy workflow already publishes SHA-1 values, but it should not be treated as collision-resistant evidence for new security-sensitive designs. Use a stronger hash such as SHA-256 when you control the protocol.
Hash the exact bytes you intend to compare
Text that looks identical can hash differently because of encoding, line endings, Unicode normalization or hidden whitespace. When matching a published digest, confirm whether the source is literal text, a file, decoded data or some other exact byte sequence before judging a mismatch.
Do not turn a digest into an authentication claim
A matching digest only means the compared byte sequences produced the same digest under the chosen algorithm. It does not prove who supplied the data. Authenticity normally requires a trusted signature, MAC or another authenticated channel in addition to a hash.
Separate passwords from general hashing
Fast general-purpose hashes are not appropriate password-storage functions because attackers can evaluate them very quickly. Password storage should use a dedicated, salted, deliberately expensive password hashing or key-derivation design chosen by the application security team.
Keep the representation beside the algorithm
Hex and Base64 can represent the same digest bytes differently. When exchanging a checksum, record both the algorithm and representation so another person does not compare a hexadecimal digest with a Base64 string and mistake a formatting difference for a content change.