Hashing
In short
Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
What is hashing?
A hash function takes input of any size, like a password, a file, or a message, and produces a fixed-size output called a hash or digest. The same input always gives the same hash, a tiny change to the input gives a completely different hash, and it should be practically impossible to work backward from the hash to the input.
Hashing is used to check that files have not been changed, to identify content (Git names every commit by a hash), to build data structures like hash tables, and to store passwords. For integrity checks and digital signatures, fast cryptographic hashes such as SHA-256 are used; older ones like MD5 and SHA-1 are broken for security purposes and should be avoided.
Passwords need special treatment. Instead of a fast hash, use a slow, salted password-hashing algorithm such as Argon2id, bcrypt, or scrypt. A salt is a random value added to each password before hashing so identical passwords produce different hashes, and the deliberate slowness makes guessing passwords from a stolen database very expensive for attackers.
Hashing is often confused with encryption. Encryption is two-way: data encrypted with a key can be decrypted with the right key. Hashing is one-way, so a server checks a login by hashing the entered password and comparing it with the stored hash, never by recovering the original password.
At a glance
Key takeaways
- A hash function maps any input to a fixed-length output.
- The same input always produces the same hash.
- Hashing is one-way, while encryption is reversible with a key.
- Use SHA-256 or stronger for integrity checks, not MD5 or SHA-1.
- Store passwords with a salted, slow algorithm like Argon2id or bcrypt.
Example
import { createHash } from "node:crypto";
import bcrypt from "bcrypt";
// Unsafe: fast and unsalted, so leaked hashes are easy to crack
const weak = createHash("sha256").update(password).digest("hex");
// Safe: bcrypt adds a random salt and is deliberately slow
const stored = await bcrypt.hash(password, 12);
// At login, compare the entered password with the stored hash
const ok = await bcrypt.compare(loginAttempt, stored);Readers ask
What is the difference between hashing and encryption?
Encryption is reversible: anyone with the right key can turn the encrypted data back into the original. Hashing is one-way, so the original input cannot be recovered from the hash, which makes it suited to verifying data rather than hiding it for later reading.
What is a salt in password hashing?
A salt is a random value generated for each password and combined with it before hashing. It ensures identical passwords get different hashes and defeats precomputed lookup tables, known as rainbow tables.
Can a hash be reversed?
A secure hash cannot be mathematically reversed, but attackers can guess inputs, hash them, and compare the results. That is why weak passwords stored with fast hashes are easy to crack, and why slow password-hashing algorithms exist.
Often compared
See also
- AlgorithmProgramming Fundamentals, p. 2An algorithm is a finite, step-by-step set of instructions for solving a problem or completing a task, such as sorting a list or finding the shortest route.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- DatabaseDatabases, p. 6A database is an organized collection of data stored on a computer, managed by software that lets applications save, search, and update it efficiently.
- GitVersion Control, p. 10Git is a free, open-source distributed version control system that tracks changes to files over time, so developers can collaborate and undo mistakes.
- SaltingSecurity, p. 34Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
- HMACSecurity, p. 15HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
- Hash CollisionData Structures, p. 17A hash collision is two different inputs sharing a hash value or bucket, which hash tables must handle and cryptographic hashes must make infeasible to find.
Sources
Spotted a mistake or something missing on this page?Suggest an edit