Security · Concept

Hashing

Turning any piece of data into a short, fixed-length fingerprint. The same input always gives the same fingerprint, and the fingerprint cannot be turned back into the data.

Crypto basics · updated

How it works

A hash function such as SHA-256 reads data of any size (a password, a file, a whole disk image) and outputs a fixed-size value: 256 bits for SHA-256, usually written as 64 hexadecimal characters. Change a single letter of the input and the output changes completely. A good hash is one-way, so the input cannot be worked out from the output, and collision-resistant, so in practice nobody can find two inputs that share a hash.

Hashes prove that data has not changed. Download pages publish checksums, Git names every commit by a hash of its contents, build tools put content hashes in file names so browsers can cache them safely, and digital signatures sign a hash rather than the whole file. MD5 and SHA-1 are broken for security use because collisions can be manufactured; SHA-256, SHA-3 and BLAKE3 are the usual choices today.

Hashing is not encryption: there is no key and nothing to decrypt. Fast hashes are also the wrong tool for passwords, which need deliberately slow password hashing.

Hashing vs the alternatives

More in Security

Crypto basics

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.