EasyWebTools

Word Up

V
developer base64 encoding hashing privacy

Cameo put out โ€œWord Up!โ€ in 1986, complete with a red codpiece and a chorus that refuses to leave your head. The title is slang for โ€œunderstood, agreed, message received.โ€

Which is the entire job of the five tools in this post. Something needs to say a thing; something else needs to receive it intact. In between sits a translation layer that most people never think about until it breaks.

Then it breaks, and you spend forty minutes wondering why your link stops working after the ampersand.

The Problem Is That Text Is Not One Thing

To you, Tom & Jerry is three words. To an HTML parser, that & is the start of an entity and everything after it is suspect. To a URL, the space is illegal and the & separates query parameters. To an email system designed in the 1970s, any byte above 127 might not survive the trip.

Same characters. Four different sets of rules about what they mean. Every one of those systems needs the text written in its own dialect, and getting it wrong produces bugs that look like the universe is broken.

The five tools below are dialect translators. Here is what each one is for, and where each one bites.

Base64: Making Binary Behave

Base64 takes arbitrary bytes and rewrites them using 64 characters that survive almost anything: A to Z, a to z, 0 to 9, plus two punctuation marks.

It exists because email was built to carry 7-bit text. Send raw binary through and something in the chain helpfully mangles it. Base64 launders the bytes into safe characters, at a cost of roughly 33% more size. That is the trade: bigger, but it arrives intact.

You have seen its output without noticing. Every data:image/png;base64,... URI is an image that has been turned into text so it can live inside an HTML or CSS file.

There is also a URL-safe variant, which swaps the two characters that cause trouble in web addresses. If your Base64 string is going into a URL, you want that mode; if it is going into an email attachment, you do not.

The thing to understand: Base64 is not encryption. There is no key. Anyone who sees the string can reverse it in one step, using the tool linked above or any of a thousand others. It hides text from a casual glance the way a cardboard box hides furniture.

URL Encoding: The Percent Signs

URL encoding, properly called percent-encoding, replaces characters that are illegal or ambiguous in a web address with a % and two hex digits. A space becomes %20. An ampersand becomes %26.

The classic bug here is choosing the wrong one of two nearly identical functions. encodeURI is for an entire address and deliberately leaves ?, &, and / alone, because those are structural. encodeURIComponent is for a single value being dropped into a query string, and escapes them.

Use the first where you needed the second and your parameter containing an & quietly splits into two parameters. The URL still looks fine. It just means something different now. Our tool has both modes precisely because the distinction is the whole ballgame.

HTML Entities: Teaching a Parser to Relax

HTML entities solve the Tom & Jerry problem from earlier. Write & and the browser displays an ampersand rather than trying to interpret what follows as a character reference.

There are three formats for the same thing: named (&), numeric (&), and hex (&). Named entities are readable; numeric ones work for characters that have no name. The tool handles all three and includes a reference table, because nobody memorises these.

Beyond cosmetics, this is a security boundary. Unescaped user input rendered straight into a page is the front door for cross-site scripting. Encoding entities is how you display what someone typed without executing it.

Hashes: The One-Way Street

A hash is different in kind from everything above. Encoding is reversible by design. Hashing is deliberately not.

Feed the same input to SHA-256 and you get the same 64-character output every time. Change one character of the input and the output changes completely. But you cannot run it backwards to recover the input, and that is the point.

It is how you verify that a download arrived uncorrupted: compare the hash you computed against the one the publisher published. Match means identical bytes. Mismatch means something changed, whether through a bad connection or something worse.

The tool computes MD5, SHA-1, SHA-256, and SHA-512 using the Web Crypto API, the same cryptographic engine your browser uses for HTTPS.

On MD5: it is fine for checking whether a file downloaded correctly. It is not fine for anything security-related. It has been possible to deliberately construct two different inputs with the same MD5 for years. Same goes for SHA-1. Reach for SHA-256 when it matters.

UUIDs: Uniqueness Without a Conversation

A UUID is a 128-bit identifier designed so that two systems can each invent one, with no coordination whatsoever, and be safe assuming they will never collide.

That property is quietly remarkable. No central registry, no database sequence, no asking permission. Version 4 fills 122 of those bits with random data, which yields enough possibilities that collision is not a practical concern.

Our generator uses crypto.randomUUID(), the browserโ€™s cryptographically secure source, rather than Math.random(). Generate up to 100 at a time, toggle uppercase, strip hyphens, copy one or all.

The Misconception That Actually Costs People

Here is the thread running through all five, and it is the reason this post exists rather than five separate ones.

Encoding is not encryption. Hashing is not encryption. Neither one keeps a secret.

Base64, percent-encoding, and HTML entities are all fully reversible with no key. Hashing is irreversible but also keyless, so a short or predictable input can simply be guessed by trying candidates until the hashes match.

If you can decode it without a key, it is not a secret. It is a costume.

People put credentials in Base64 and believe they have hidden them. They store passwords as bare MD5 and believe they are protected. Both mistakes are still shipping today, in production, at companies that should know better.

Encryption needs a key that the other party does not have. Everything in this post is public math. Useful public math, running dozens of times per second in every page you load, but public.

Message Received

All five tools run entirely in your browser. Your text, your files, your hashes: none of it is uploaded anywhere, which for a hash generator is more than a nicety. The thing you are hashing is often the thing you would least like to send to a stranger.

Try them here: Base64, URL encoder, HTML entities, hash generator, UUID generator.

Cameo were right. Word up: understood, agreed, message received, and arriving in one piece with the ampersand still attached.

(We wanted to Base64-encode this entire post as a joke. It came out 33% longer and no funnier, which is roughly what the specification promised.)