Side by side
EncryptionvsHashing
What is the difference between encryption and hashing?
Updated 2 min read7 differences
In short
Encryption scrambles data with a key so it can be decrypted later, while hashing makes a fixed-length fingerprint that can't be reversed, ideal for passwords.
Encryption
Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
Read the page on EncryptionHashing
Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
Read the page on HashingEncryption and Hashing compared
| Aspect | Encryption | Hashing |
|---|---|---|
| Direction | Two-way: decrypt with the right key | One-way: cannot be reversed |
| Key | Requires a key, either shared or a public/private pair | No key needed; HMAC variants add a secret key |
| Output size | Grows with the size of the input | Fixed length, such as 256 bits for SHA-256 |
| Same input | Can give different ciphertext each time | Always gives the same hash |
| Purpose | Keep data confidential | Verify integrity and compare values |
| Typical uses | HTTPS, disk encryption, messaging, backups | Password storage, checksums, signatures, deduplication |
| Common algorithms | AES, ChaCha20, RSA, elliptic-curve schemes | SHA-256, SHA-3, BLAKE3; Argon2 and bcrypt for passwords |
The difference, explained
Encryption transforms readable data, called plaintext, into unreadable ciphertext using an algorithm and a key, and anyone with the right key can turn it back. Hashing runs data through a one-way function that always produces a fixed-size output, called a hash or digest, such as the 256-bit result of SHA-256.
The core difference is reversibility, and it follows from their purpose. Encryption protects data you will need to read again, like messages, backups or card numbers, so it must be reversible for authorized parties. Hashing proves that data matches or has not changed: the same input always produces the same hash, but you cannot recover the input from it.
They are often used together. TLS, the security layer behind HTTPS, encrypts traffic but relies on hash functions to derive keys and verify handshake messages, and digital signatures hash a document before signing it with a private key. Password storage uses special slow, salted hashes such as Argon2, scrypt or bcrypt so that stolen hashes are hard to crack.
A common misconception is that encoding such as Base64 is encryption, or that hashing passwords with plain SHA-256 is enough. Base64 can be reversed by anyone without a key, and fast hashes can be guessed at billions of attempts per second on modern GPUs, which is why passwords need a deliberately slow hash with a unique salt.
Which one should you use?
Choose Encryption when…
- You need to read the original data again later.
- Data must stay private in transit or at rest, like messages or files.
- Only people or systems holding a key should access the content.
Choose Hashing when…
- You only need to check that a value matches, as with passwords.
- You want to detect whether a file or message has changed.
- You need a short, fixed-size fingerprint for lookups or deduplication.
Reversible encryption vs a one-way hash
from cryptography.fernet import Fernet
key = Fernet.generate_key() # keep this secret
box = Fernet(key)
token = box.encrypt(b"card 4242 4242 4242 4242")
print(box.decrypt(token)) # the original bytes come backimport hashlib
digest = hashlib.sha256(b"hello world").hexdigest()
print(digest) # always the same 64 hex characters
# There is no "decrypt": you can only hash again and compare
print(hashlib.sha256(b"hello world").hexdigest() == digest)
# For passwords, use a slow salted hash like Argon2 or bcryptReaders ask
Can a hash be decrypted?
No. A hash function is one-way, so there is nothing to decrypt. Attackers instead guess inputs and compare the hashes, which is why weak or unsalted password hashes can still be cracked.
Should passwords be encrypted or hashed?
Hashed, with a slow, salted algorithm designed for passwords, such as Argon2, scrypt or bcrypt. Encrypted passwords could all be revealed at once if the key leaked.
Is Base64 encryption?
No. Base64 is an encoding that makes binary data safe to send as text, and anyone can decode it without a key.