Detect Edited Photos with a SHA-256 Fingerprint
SHA-256 in plain language: what a match proves, what a mismatch means, why photos sent via Zalo or Messenger never match, how to compare files.
The most reliable way to tell whether an image file has been changed since it was first recorded is to compare the SHA-256 fingerprints of the two files: a match means they are identical byte for byte, a mismatch means the file has changed. But “changed” is not the same as “faked”: simply sending a photo through Zalo or Messenger is enough to break the match. This guide explains SHA-256 in plain terms, what it does and does not prove, and a workflow that holds up in practice.
Note: This article is general information, not legal advice. How evidence is weighed in a given case is for the relevant authority to decide.
What SHA-256 is, in plain language
Think of SHA-256 as a machine that makes a fingerprint for a file. Feed it any file, a 3 MB photo or a 2 GB video, and it returns a fixed string of 64 characters, something starting like 9f2c1a…. The algorithm is specified in the US NIST standard FIPS 180-4 and is used everywhere from banking to software downloads.
Three properties matter:
- Same file, same fingerprint. However many times and on whatever computer you compute it, you get the same string.
- A tiny change, a completely different result. Change one pixel or remove one line of metadata, and the new fingerprint bears no resemblance to the old one. There is no “nearly matching”.
- One-way. You cannot rebuild the photo from the fingerprint, and in practice nobody can deliberately craft a different file with the same fingerprint.
That means storing 64 characters when a photo arrives is enough to check, later, whether any file is exactly that photo, without keeping or resending the image itself.
What a match proves, and what a mismatch tells you
| Result | Proves | Does not prove |
|---|---|---|
| Match | The file you hold is byte-identical to the file whose fingerprint was stored | That the scene is genuine, or that nothing was staged before the shot |
| Mismatch | The file differs from the original in some way | That someone deliberately altered the content |
The second row is where people go wrong. Files drift from the original for many harmless reasons:
- Chat apps recompress images. Zalo, Messenger and many others shrink and recompress photos sent as “photos”.
- Social networks recompress and strip metadata when you post.
- Screenshots instead of sending the file.
- Rotating, cropping or tweaking brightness, even slightly, in the gallery app.
- Converting formats, for example HEIC to JPEG, or “save as” from a viewer.
So when you see a mismatch, the right question is not “is this fake?” but “which channels did this file pass through?”
Why photos sent via Zalo or Messenger never match
To save storage and bandwidth, messaging apps typically re-encode JPEG images: lower resolution, stronger compression, less metadata. To the eye the picture looks the same, but the bytes inside are completely different, so the SHA-256 is too.
| How it was sent | Usually keeps the original file? | SHA-256 comparison |
|---|---|---|
| As a “photo” in a chat app | No, recompressed | Almost certainly no match |
| As a “file” or document in a chat app | Usually yes | Usually matches |
| Email attachment | Usually yes | Usually matches |
| Original downloaded from Google Drive or OneDrive | Yes | Matches |
| Screenshot | No | No match |
The QR code printed on the photo usually still scans after compression, so the recipient can check capture time and area even when the fingerprint comparison fails. See QR photo verification.
A practical comparison workflow
If you send the photos (contractors, technicians, field staff)
- Sending quick photos over chat for day-to-day updates is fine.
- For photos that matter (inspections, handovers, insurance claims), also send the original as a file, by email or through a shared folder.
- Do not crop, rotate or edit before sending the original.
- Put the SnapID code in your message so the recipient can look it up quickly.
If you receive the photos (owners, clients, managers, insurers)
- Scan the QR code or open the verification page from the code on the photo.
- Check capture time, area and the integrity flags.
- Click compare with my file and choose the original you received.
- Match: the file is intact. No match: check whether it went through a compressing channel, then ask for the original.
- If an original sent through a non-compressing channel still does not match, ask the sender and look closely at the thumbnail on the verification page.
Computing SHA-256 yourself
For your own checks or record-keeping, built-in tools are enough:
- Windows (Command Prompt):
certutil -hashfile photo.jpg SHA256 - macOS (Terminal):
shasum -a 256 photo.jpg - Linux:
sha256sum photo.jpg
Compare the output with the string the sender gave you. One differing character means two different files.
How SnapID Mark uses SHA-256
When a SnapID Mark photo is uploaded, the server stores SHA-256 fingerprints of both the original and the stamped image. The public verification page shows the fingerprint alongside the trusted capture time, a rounded area and the integrity flags. The “compare with my file” button computes SHA-256 inside the recipient’s browser, so the photo is not uploaded, and checks it against the stored value. The page also explains the chat-app recompression case so recipients do not jump to conclusions.
Together that gives three layers: trusted time says when (see trusted time vs phone time), the SnapID code and QR lead to an independent record, and SHA-256 says whether the file is still intact. Learn more under security or try the verify demo.
Keep in mind that this is a technical checking tool, not a digital signature or a certified timestamp. Timestamped photos as evidence in Vietnam looks at that side in more depth.
If you need to send photos whose integrity the recipient can check for themselves, download SnapID Mark and try comparing an original against a copy sent over chat.
FAQ
Does a SHA-256 fingerprint reveal what is in the photo?
No. The image cannot be rebuilt from 64 characters, so showing the fingerprint publicly does not expose the picture.
A photo sent through Zalo does not match. Is it fake?
No. Zalo recompresses images sent as “photos”, which changes the file even though it looks identical. Ask for the original sent as a file or by email and compare that.
When I compare on the verification page, is my photo uploaded?
No. Your browser computes the fingerprint on your device; the image file never leaves it.
Does a match mean the photo is definitely genuine?
A match only proves the file is identical to the one stored at upload. It does not prove the scene was not staged. Look at the time, area and integrity flags as well.
Can I compare a PDF exported from the photo?
Do not use a PDF for the comparison, because the image inside it is a different file. Compare using the original JPEG.