A hash function turns any input, from a single letter to a whole movie, into a short fixed-size fingerprint. The same input always gives the same fingerprint; a different input gives a completely different one; and there is no practical way to go backwards from the fingerprint to the input. Make one with the Hash Generator.
Properties of a good hash
- Deterministic.
hellohashed with SHA-256 is always2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824. - Fixed length. The hash of an empty string and the hash of a 4 GB file are both 64 hex characters (256 bits) with SHA-256.
- Avalanche effect. Change one letter and about half the output bits flip.
helloandhellpdiffer by one character, yet their SHA-256 hashes differ in 131 of 256 bits:fdd7585e08c4e2afd71dcabdb4636c89d557a3f42db9e2040c8bbd1708aa4ce7. - One-way. Knowing the hash does not let you recover the input, except by guessing inputs and hashing them.
- Collision resistant. It should be infeasible to find two different inputs with the same hash.
Common algorithms
| Algorithm | Output size | Hex length | Status |
|---|---|---|---|
| MD5 | 128 bits | 32 | Broken: collisions are easy. Fine only for non-security checksums |
| SHA-1 | 160 bits | 40 | Broken for signatures: practical collisions exist. Avoid |
| SHA-256 | 256 bits | 64 | Secure; the standard choice |
| SHA-512 | 512 bits | 128 | Secure; often faster than SHA-256 on 64-bit CPUs |
| SHA3-256 | 256 bits | 64 | Secure; a different design from the SHA-2 family |
What hashes are used for
- Checking file integrity. Publish a download's SHA-256 so people can confirm they got the exact file. A single flipped bit gives a different hash.
- Digital signatures. Sign the hash of a message instead of the whole message.
- De-duplication and caching. Identical content has an identical hash.
- Storing passwords, but only with the special methods below. A plain SHA-256 is the wrong tool.
- Message authentication. HMAC mixes a secret key into the hash: HMAC-SHA-256 of
The quick brown fox jumps over the lazy dogwith the keykeyisf7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8. Only someone with the key can produce or check it.
Hashing is not encryption
Encryption can be reversed with a key; a hash cannot be reversed at all. A hash also cannot tell you a file is safe, only that it is unchanged since the hash was made.
Storing passwords properly
Fast hashes are the problem: an attacker with a stolen database can test billions of SHA-256 guesses per second on a graphics card, and common passwords fall instantly.
- Add a salt, a unique random value per user stored with the hash. Two users with the same password then get different hashes, and precomputed "rainbow tables" are useless.
- Use a deliberately slow, memory-hungry password hash: Argon2id (preferred), scrypt, bcrypt or PBKDF2 with a high iteration count. Try bcrypt with the Bcrypt Generator.
- Never invent your own scheme or store passwords in plain text, reversibly encrypted, or with MD5 or SHA-1.
Judge how guessable a password is with the Password Strength & Entropy Auditor.
Common mistakes
- Using MD5 or SHA-1 where security matters.
- Comparing hashes with a normal string comparison when they guard secrets. Use a constant-time comparison to avoid timing leaks.
- Hashing short or predictable inputs (a phone number, a birthday) and calling the result anonymous. Anyone can hash every possible value and look it up.