secureSHA-2 · 384 bits · 2001
SHA-384
Truncated SHA-512: the awkward middle child of the SHA-2 family. Mandated by NSA Suite B at the TOP SECRET level.
By Deepak Gupta ·
SHA-384 is SHA-512 computed with a different IV and truncated to 384 bits. It's the SHA-2 family member you encounter when an enterprise crypto policy demands a 192-bit security level (matching AES-256), most famously the NSA's Commercial National Security Algorithm Suite for classified work. For practical purposes it's no more secure than SHA-256 for most threat models. The extra bits matter only if you're worried about a future quantum attacker with Grover's algorithm halving your effective hash strength.
Recommended uses
- ·Compliance with NSA CNSA / Suite B requirements
- ·Forward-secrecy-conscious systems planning for post-quantum attackers
Known attacks / caveats
- ·Length-extension does NOT apply (the truncation in the IV prevents it)
Designed by
NSA, published 2001.
Frequently asked questions
- Is SHA-384 secure in 2026?
- Yes. SHA-384 has no practical breaks as of 2026. Caveats worth knowing: Length-extension does NOT apply (the truncation in the IV prevents it).
- What is SHA-384 used for?
- Compliance with NSA CNSA / Suite B requirements. Forward-secrecy-conscious systems planning for post-quantum attackers.
- How long is the output of SHA-384?
- 384 bits, which is 48 bytes, or 96 characters when written as hexadecimal. The length is fixed regardless of how large the input is.
- Can SHA-384 be used to hash passwords?
- No, and this is the most consequential mistake people make with it. SHA-384 is a fast general-purpose hash, and fast is exactly the wrong property for passwords: it lets an attacker with a stolen database test billions of guesses. Use a purpose-built password hashing function such as Argon2id instead.
- Who created SHA-384?
- NSA, published in 2001.