Mastodon Mastodon Mastodon Mastodon

Hash

Updated: · CyberSecureFox Editorial Team

A hash is a fixed-length value calculated from data by a one-way hash function; the same input always gives the same hash, and the original data cannot be recovered from it.

How hash functions work

A cryptographic hash function takes input of any size – a password, a file, a whole disk image – and produces a short “fingerprint” such as a 256-bit SHA-256 value. A good function has three properties: it cannot be reversed, two different inputs practically never produce the same hash (collision resistance), and changing a single bit of input changes the result completely.

MD5 and SHA-1 are considered broken: researchers produced practical collisions, including the SHAttered attack on SHA-1 in 2017. Today SHA-256, SHA-3 and BLAKE2 are the usual choices.

Where hashes are used

  • Integrity checks – comparing a downloaded file with the vendor’s published hash, or verifying software updates.
  • Threat detection – file hashes are a classic indicator of compromise shared in threat reports.
  • Password storage – services keep a hash of each password with a random salt instead of the password itself.
  • Digital signatures and blockchains – both sign or chain hashes rather than raw data.

Attacks on hashes

A hash is not encryption, but weak password hashes can still be “cracked”: attackers who steal a database run brute force and dictionary attacks on GPUs with tools like hashcat, or use precomputed rainbow tables. In Windows networks, pass-the-hash attacks reuse NTLM hashes directly without knowing the password.

Best practices

For passwords use deliberately slow, salted algorithms – Argon2, bcrypt or scrypt – and never plain MD5 or SHA-1. For integrity checks, use SHA-256 or stronger.

Synonyms:
hash function, cryptographic hash, hash value