Security · Comparison

Hashing vs encryption vs HMAC

Three building blocks that are easy to mix up. Hashing makes a fingerprint, encryption hides data until the right key reveals it, and HMAC proves a message came from someone who holds a shared secret.

3 options · 8 questions side by side · updated

CompareHashingEncryptionHMAC
What it doesMakes a fixed-size fingerprint of dataScrambles data so only a key holder can read itMakes a keyed fingerprint that proves the sender
ReversibleNo, one-way by designYes, with the right keyNo, the receiver recomputes and compares
Keys neededNoneOne shared key, or a public and private pairOne secret shared by sender and receiver
Same input, same outputAlwaysUsually not, a random nonce varies itAlways, for the same key
Common algorithmsSHA-256, SHA-3, BLAKE3AES-GCM, ChaCha20-Poly1305, RSA, elliptic curvesHMAC-SHA256
ProvesThe data has not changedOnly key holders can read itUnchanged, and sent by a key holder
Typical useChecksums, Git, cache-busting file namesHTTPS, disk and database encryption, chat appsWebhook signatures, payment callbacks, JWTs
Watch out forFast hashes are wrong for passwordsKeys stored beside the data they protectCompare in constant time, reject old timestamps

How to choose between Hashing, Encryption and HMAC

  • Use a hash to check that data has not changed, and a slow password hash such as Argon2id or bcrypt for passwords.
  • Use encryption when data must be read again later by someone who holds the key.
  • Use HMAC when a receiver must be sure a message came from a partner who shares a secret, as with webhooks and payment callbacks.

The options

More comparisons

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.