SHA-512
In short: A hashing algorithm from the SHA-2 family that produces a 512-bit (64-byte) hash value — the “big brother” of SHA-256.
In more detail: SHA-512 works internally with 64-bit words instead of 32-bit like SHA-256, which often makes it even faster than SHA-256 on 64-bit processors, despite the output value being twice as long. The longer output theoretically offers more resistance against collision attacks; in practice SHA-256 is considered sufficiently secure for most use cases.
In Depth
The internal structure of SHA-512 is almost identical to SHA-256 (both are based on the same Merkle-Damgård construction), just with larger internal state variables and more rounds:
SHA-256: 32-bit words, 64 rounds, 256-bit output
SHA-512: 64-bit words, 80 rounds, 512-bit output
On modern 64-bit servers (practically every server processor today), SHA-512 can thereby work more efficiently per byte than SHA-256, because the internal 64-bit operations are executed directly in a single processor instruction, whereas SHA-256 needs two 32-bit operations for the same amount of data. On 32-bit systems (e.g. some embedded devices), the advantage reverses — there SHA-256 is usually faster.
There’s also SHA-384, a variant that computes internally like SHA-512 but truncates the output to 384 bits (through different initialisation values, not simply by cutting it off) — useful when a somewhat shorter, but still very secure, hash is wanted. For the vast majority of applications (TLS certificates, signatures, file integrity), the security gain of SHA-512 over SHA-256 is practically negligible — both are considered cryptographically secure, and SHA-256 has become the de-facto standard simply because it performs equally well on more systems (especially 32-bit and embedded systems).
Typical uses of SHA-512
In practice SHA-512 is encountered directly less often than SHA-256, but it’s the basis of several widely used systems: Linux systems often use SHA-512-based crypt (the $6$ prefix in /etc/shadow) for hashed user passwords. Digital signature schemes with high security requirements (e.g. certain government or military systems) prefer SHA-512, to benefit from the larger theoretical security margin, even if it doesn’t need to be practically exploited for the foreseeable future. Some blockchain and cryptocurrency systems beyond Bitcoin (which uses SHA-256) also rely on SHA-512 or variants of it.
SHA-2 vs. SHA-3 competition
In addition to the SHA-2 family (to which SHA-256 and SHA-512 belong), NIST published a completely new, structurally independent hash standard, SHA-3, in 2015 — not because SHA-2 was broken, but as a precautionary safeguard (“diversity”), in case a structural weakness were ever found in SHA-2 in the future. SHA-3 is based on a completely different internal construction (the Keccak sponge function instead of Merkle-Damgård) and so far is used considerably less often than SHA-2, since SHA-2 (including SHA-256 and SHA-512) is still considered fully secure and there’s correspondingly little urgency to switch.
Why the theoretical security margin is rarely practically relevant
A 512-bit hash theoretically offers collision resistance of 2^256 (because of the birthday paradox, practical security against collisions is roughly half the bit length) — a number that exceeds any imagination and is far beyond what could be attacked with today’s or foreseeable future computing power. SHA-256, with 2^128 collision resistance, also offers an astronomically large security margin — the difference between “unimaginably secure” and “even more unimaginably secure” is barely relevant for practical purposes. The choice between SHA-256 and SHA-512 is therefore almost never made in practice based on security considerations, but based on performance on the target platform and the conventions of the system or standard being used.