see https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html would be better to use sha256, or even better something like scrypt or bcrypt (which are actually meant for password hashing)