What is a hash, and why can’t you reverse it?

A hash is a unique-looking, fixed-length string of characters generated from data such as a password, message, or file.

You can think of it like a digital fingerprint for data. If you give the same data to the same hash function, you will always get the same hash. But if you change even a single character, the resulting hash will be completely different.

A hash function takes an input and processes it through a mathematical algorithm to produce a fixed-size output called a hash or hash value.

For example, using SHA-256:

echo -n "hello" | sha256sum

The result is:

2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824

Now change hello to Hello:

echo -n "Hello" | sha256sum

You will get a completely different hash, even though only one character was changed.

Three important properties make hashing useful:

  • Same input → same hash: The same data produces the same result when the same hash algorithm is used.
  • Small change → big difference: Changing even one character can produce a drastically different hash.
  • Fixed length: SHA-256 always produces a 256-bit hash, regardless of whether the input is one word or a large file.

A cryptographic hash function is designed to be one-way. You can easily calculate a hash from the original data, but you should not be able to practically recover the original data from the hash.

This is because hashing compresses data into a fixed-size value, meaning the original information is not preserved in a reversible form.

However, this does not mean hashes are impossible to guess. An attacker can try possible inputs, hash them, and compare the results. This is why weak passwords can still be discovered.

Hashes are widely used in cybersecurity.

Password protection: Websites should not store your actual password. Instead, they store a securely generated password hash. When you log in, your entered password is processed and compared against the stored value. Modern systems also use techniques such as salting and slow password-hashing algorithms to make guessing attacks more difficult.

File integrity: Hashes can also help verify that a file has not been changed. If a website publishes the expected hash of a download, you can calculate the hash of your copy and compare the two values.

If you have Linux, open a terminal and run:

echo -n "hello" | sha256sum

Then change hello to Hello and run the command again.

Notice how dramatically the hash changes.

Note: On macOS, you can use shasum -a 256 instead of sha256sum.

  • A hash is a fixed-length representation of data.
  • The same input produces the same hash when using the same algorithm.
  • A tiny change in the input can produce a completely different hash.
  • Cryptographic hashes are designed to be one-way.
  • Hashes are commonly used for password protection and file integrity.
  • Hashing is different from encryption because encryption is designed to be reversible with the appropriate key.

Continue with Passwords, Hashing & Salting to learn how hashes are used to protect passwords and why adding a salt makes password attacks harder.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *