Skip to content
lesson Data security and encryption Intermediate 3 min read

Encryption vs hashing: what’s the difference?

Encryption can be reversed with a key. Hashing cannot be reversed at all. What each is for, and which one should protect what.

Encryption and hashing both turn readable data into something unreadable, which is why they get confused. The difference is whether the original can be recovered. Encrypted data can be decrypted by anyone who holds the key. A hash cannot be turned back into the original by anyone.

What each one is

Encryption uses an algorithm and a key to turn plaintext into ciphertext, and a key turns it back. Its job is confidentiality: keeping data unreadable to everyone except the people authorised to see it.

Hashing puts data through a one-way function that produces a short value of fixed length. It uses no key. Its job is checking: that a file has not changed, or that two things match, without the original having to be kept or shown.

The differences side by side

  • Can it be reversed? Encryption can, with the key. Hashing cannot.
  • Is there a key? Encryption has one, and it must be kept safe. Hashing has none.
  • What comes out? Encryption gives ciphertext that still holds all of the original. Hashing gives a value of the same length whatever the size of the input.
  • What is it for? Encryption keeps data secret until an authorised person needs it. Hashing lets you check data.

Which one for which job

  • Files on a laptop, phone, server or backup: encryption, because you need to read them again.
  • Data crossing the internet: encryption.
  • Passwords: hashing, with a salt. The system only has to check a password and never has to read it.
  • Confirming that a file or message has not changed: hashing.
  • Digital signatures: both together. The document is hashed, and the hash is signed with a private key.

The mix-ups to watch for

The first is passwords described as “encrypted”. If passwords are encrypted, a key exists that turns every one of them back into readable text, and whoever steals that key along with the database has them all. NIST’s guidance is that stored passwords must be salted and hashed. It allows a secret key as an extra layer on top of the hashing, provided the key is stored separately from the hashes.

The second is expecting a hash to hide something that is easy to guess. An attacker can hash every likely value and compare the results. The UK’s National Cyber Security Centre describes this as the way passwords are recovered from stolen hashes, and it is the reason for the salt.

Questions to ask a supplier

  • How are user passwords stored?
  • Is our data encrypted where it is stored and while it travels?
  • Who holds the encryption keys, and who is able to decrypt the data?

The Office of the Australian Information Commissioner asks businesses much the same things about their own systems. They also belong in A cyber security checklist for small business. If you are having software built, see software development.

Sources

  1. Glossary: encryption (NIST Computer Security Resource Center) csrc.nist.gov
  2. Glossary: hash function (NIST Computer Security Resource Center) csrc.nist.gov
  3. Glossary: digital signature (NIST Computer Security Resource Center) csrc.nist.gov
  4. Information security manual: Guidelines for cryptography (Australian Signals Directorate) cyber.gov.au
  5. SP 800-63B-4: Digital identity guidelines, authentication and authenticator management (NIST) pages.nist.gov
  6. Password policy: updating your approach (UK National Cyber Security Centre) ncsc.gov.uk
  7. Guide to securing personal information (Office of the Australian Information Commissioner) oaic.gov.au

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.