Hashing
Field: Security · Also called: hash function, cryptographic hash function, message digest
Hashing is the use of a cryptographic hash function to map input of any length to a fixed-length digest, in a way that is one-way and deterministic, so the same input always yields the same digest and the input cannot be computed back from it.
Properties
NIST describes a cryptographic hash function by three security properties:
- Preimage resistance: given an output, it is computationally infeasible to find any input that produces it.
- Second preimage resistance: given one input, it is computationally infeasible to find a different input with the same output.
- Collision resistance: it is computationally infeasible to find any two distinct inputs with the same output.
A collision in this sense means two different inputs producing the same digest. Two identical inputs producing the same digest is not a collision. It is the deterministic behavior hash functions are designed to have, and it is the reason password hashing adds a salt.
Hashing is not encryption
Encryption is reversible by anyone holding the key. A hash function has no key and no inverse. A stored password hash is therefore not “decrypted” by an attacker. It is cracked by hashing candidate passwords and comparing the results to the stored digest.
Uses
Hashing is used to detect changes to data, supporting integrity. Digital signature schemes sign a digest of the message, not the message itself, which is how hashing supports non-repudiation. Hash functions are also building blocks in keyed constructions such as HMAC and in password hashing schemes such as PBKDF2.
Standard algorithms
The SHA-2 family (SHA-224, SHA-256, SHA-384, SHA-512, and variants) is specified in FIPS 180-4, and SHA-3 in FIPS 202. In December 2022, NIST announced that SHA-1 should be phased out by December 31, 2030, citing collision attacks that have undermined it.
General-purpose hash functions like these are designed to be fast. That is a strength for integrity checking and a weakness for storing passwords; see Password Hashing.
Sources
- hash function, NIST Computer Security Resource Center Glossary (definitions from FIPS 186-5 and SP 800-108r1). Retrieved October 2, 2026.
- FIPS 180-4, Secure Hash Standard (SHS), NIST. Retrieved October 2, 2026.
- FIPS 202, SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions, NIST. Retrieved October 2, 2026.
- NIST Retires SHA-1 Cryptographic Algorithm, NIST, December 15, 2022. Retrieved October 2, 2026.
- RFC 2104, HMAC: Keyed-Hashing for Message Authentication, IETF, 1997. Retrieved October 2, 2026.
See also
Go deeper
Articles
- What is the difference between bcrypt and SHA256? February 5, 2016
- Really Bad Passwords (with Unsalted Hashes) June 8, 2012
- Authentication Without Encryption for Ham Radio August 17, 2009