Skip to main content

Side by side

EncryptionvsHashing

What is the difference between encryption and hashing?

Updated 2 min read7 differences

In short

Encryption scrambles data with a key so it can be decrypted later, while hashing makes a fixed-length fingerprint that can't be reversed, ideal for passwords.

Encryption

Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.

Read the page on Encryption

Hashing

Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.

Read the page on Hashing

Encryption and Hashing compared

AspectEncryptionHashing
DirectionTwo-way: decrypt with the right keyOne-way: cannot be reversed
KeyRequires a key, either shared or a public/private pairNo key needed; HMAC variants add a secret key
Output sizeGrows with the size of the inputFixed length, such as 256 bits for SHA-256
Same inputCan give different ciphertext each timeAlways gives the same hash
PurposeKeep data confidentialVerify integrity and compare values
Typical usesHTTPS, disk encryption, messaging, backupsPassword storage, checksums, signatures, deduplication
Common algorithmsAES, ChaCha20, RSA, elliptic-curve schemesSHA-256, SHA-3, BLAKE3; Argon2 and bcrypt for passwords

The difference, explained

Encryption transforms readable data, called plaintext, into unreadable ciphertext using an algorithm and a key, and anyone with the right key can turn it back. Hashing runs data through a one-way function that always produces a fixed-size output, called a hash or digest, such as the 256-bit result of SHA-256.

The core difference is reversibility, and it follows from their purpose. Encryption protects data you will need to read again, like messages, backups or card numbers, so it must be reversible for authorized parties. Hashing proves that data matches or has not changed: the same input always produces the same hash, but you cannot recover the input from it.

They are often used together. TLS, the security layer behind HTTPS, encrypts traffic but relies on hash functions to derive keys and verify handshake messages, and digital signatures hash a document before signing it with a private key. Password storage uses special slow, salted hashes such as Argon2, scrypt or bcrypt so that stolen hashes are hard to crack.

A common misconception is that encoding such as Base64 is encryption, or that hashing passwords with plain SHA-256 is enough. Base64 can be reversed by anyone without a key, and fast hashes can be guessed at billions of attempts per second on modern GPUs, which is why passwords need a deliberately slow hash with a unique salt.

Which one should you use?

Choose Encryption when…

  • You need to read the original data again later.
  • Data must stay private in transit or at rest, like messages or files.
  • Only people or systems holding a key should access the content.

Choose Hashing when…

  • You only need to check that a value matches, as with passwords.
  • You want to detect whether a file or message has changed.
  • You need a short, fixed-size fingerprint for lookups or deduplication.

Reversible encryption vs a one-way hash

Encryptionpython
from cryptography.fernet import Fernet

key = Fernet.generate_key()  # keep this secret
box = Fernet(key)

token = box.encrypt(b"card 4242 4242 4242 4242")
print(box.decrypt(token))  # the original bytes come back
Hashingpython
import hashlib

digest = hashlib.sha256(b"hello world").hexdigest()
print(digest)  # always the same 64 hex characters

# There is no "decrypt": you can only hash again and compare
print(hashlib.sha256(b"hello world").hexdigest() == digest)
# For passwords, use a slow salted hash like Argon2 or bcrypt

Readers ask

Can a hash be decrypted?

No. A hash function is one-way, so there is nothing to decrypt. Attackers instead guess inputs and compare the hashes, which is why weak or unsalted password hashes can still be cracked.

Should passwords be encrypted or hashed?

Hashed, with a slow, salted algorithm designed for passwords, such as Argon2, scrypt or bcrypt. Encrypted passwords could all be revealed at once if the key leaked.

Is Base64 encryption?

No. Base64 is an encoding that makes binary data safe to send as text, and anyone can decode it without a key.

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings