Skip to content
lesson Data security and encryption Beginner 3 min read

What is hashing?

Hashing turns any data into a short fingerprint that cannot be turned back. How it works, and why passwords should be stored this way.

Hashing runs data through a function that produces a short, fixed-length value called a hash. The same input always gives the same hash, and there is no practical way to work backwards from the hash to the input.

A fingerprint for data

NIST describes a hash as a fingerprint of a file or message. A fingerprint identifies a person without telling you anything else about them, and you cannot rebuild the person from it. A hash function takes input of any length, from one word to a whole disk, and gives back a value that is always the same size.

A hash function fit for security work has two properties. It is one-way: finding an input that produces a given hash is not practical. It is collision resistant: finding two different inputs that produce the same hash is not practical either. There is no key involved, so there is no key to keep safe.

Spotting changes

The first use is detecting change. Record the hash of a file, then hash the file again later. If the two values differ, the file is not the one you started with. Systems use this to confirm that a file or message arrived intact. Digital signatures rely on it too: the document is hashed first, and the signature is applied to the hash.

Why passwords are stored as hashes

A service never needs to read your password back. It only needs to check that what you type now matches what you chose earlier. So a well-built system keeps the hash and throws the password away. If its user database is stolen, the thief has the hashes and still does not know the passwords.

Thieves then guess. They hash long lists of likely passwords and look for matches. NIST and the UK’s National Cyber Security Centre (NCSC) both call for two defences:

  • A salt: a random value added to each password before it is hashed. Two people with the same password then get different hashes, and tables of hashes worked out in advance are no use.
  • A hashing scheme built for passwords, which repeats the work many times so that every guess costs the attacker more.

Hashing slows the guessing down without ending it. NCSC warns that an attacker with enough computing power may still recover some passwords, which is one more reason to make them long and never use the same one twice.

What to ask

When you buy or commission software that holds logins, ask how the passwords are stored. The Office of the Australian Information Commissioner puts the same question to any business that holds personal information. The answer to look for is “salted and hashed, with a current password hashing scheme”. The Australian Signals Directorate approves only the SHA-2 family of hash functions for general use, so an older algorithm is a reason to ask more.

A stolen password database is the reason reused passwords are dangerous. That is covered in Why reusing passwords is still one of the biggest security risks.

Sources

  1. Glossary: hash function (NIST Computer Security Resource Center) csrc.nist.gov
  2. FIPS 180-4: Secure Hash Standard (NIST) csrc.nist.gov
  3. Password policy: updating your approach (UK National Cyber Security Centre) ncsc.gov.uk
  4. SP 800-63B-4: Digital identity guidelines, authentication and authenticator management (NIST) pages.nist.gov
  5. Information security manual: Guidelines for cryptography (Australian Signals Directorate) cyber.gov.au
  6. Guide to securing personal information (Office of the Australian Information Commissioner) oaic.gov.au

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.