# Hashing

URL: https://softwaredictionary.org/terms/hashing
Category: Security
Last updated: 2026-09-29

In short: Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.

## What is hashing?

A hash function takes input of any size, like a password, a file, or a message, and produces a fixed-size output called a hash or digest. The same input always gives the same hash, a tiny change to the input gives a completely different hash, and it should be practically impossible to work backward from the hash to the input.

Hashing is used to check that files have not been changed, to identify content (Git names every commit by a hash), to build data structures like hash tables, and to store passwords. For integrity checks and digital signatures, fast cryptographic hashes such as SHA-256 are used; older ones like MD5 and SHA-1 are broken for security purposes and should be avoided.

Passwords need special treatment. Instead of a fast hash, use a slow, salted password-hashing algorithm such as Argon2id, bcrypt, or scrypt. A salt is a random value added to each password before hashing so identical passwords produce different hashes, and the deliberate slowness makes guessing passwords from a stolen database very expensive for attackers.

Hashing is often confused with encryption. Encryption is two-way: data encrypted with a key can be decrypted with the right key. Hashing is one-way, so a server checks a login by hashing the entered password and comparing it with the stored hash, never by recovering the original password.

## Key takeaways

- A hash function maps any input to a fixed-length output.
- The same input always produces the same hash.
- Hashing is one-way, while encryption is reversible with a key.
- Use SHA-256 or stronger for integrity checks, not MD5 or SHA-1.
- Store passwords with a salted, slow algorithm like Argon2id or bcrypt.

## Example: Unsafe vs. safe password storage (Node.js)

```javascript
import { createHash } from "node:crypto";
import bcrypt from "bcrypt";

// Unsafe: fast and unsalted, so leaked hashes are easy to crack
const weak = createHash("sha256").update(password).digest("hex");

// Safe: bcrypt adds a random salt and is deliberately slow
const stored = await bcrypt.hash(password, 12);

// At login, compare the entered password with the stored hash
const ok = await bcrypt.compare(loginAttempt, stored);
```

## Frequently asked questions

**What is the difference between hashing and encryption?**

Encryption is reversible: anyone with the right key can turn the encrypted data back into the original. Hashing is one-way, so the original input cannot be recovered from the hash, which makes it suited to verifying data rather than hiding it for later reading.

**What is a salt in password hashing?**

A salt is a random value generated for each password and combined with it before hashing. It ensures identical passwords get different hashes and defeats precomputed lookup tables, known as rainbow tables.

**Can a hash be reversed?**

A secure hash cannot be mathematically reversed, but attackers can guess inputs, hash them, and compare the results. That is why weak passwords stored with fast hashes are easy to crack, and why slow password-hashing algorithms exist.

## Sources

- [NIST FIPS 180-4: Secure Hash Standard (SHS)](https://csrc.nist.gov/pubs/fips/180-4/upd1/final)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
