What is a hash, and why can’t you reverse it?
What Is a Hash?
A hash is a unique-looking, fixed-length string of characters generated from data such as a password, message, or file.
You can think of it like a digital fingerprint for data. If you give the same data to the same hash function, you will always get the same hash. But if you change even a single character, the resulting hash will be completely different.
How Does Hashing Work?
A hash function takes an input and processes it through a mathematical algorithm to produce a fixed-size output called a hash or hash value.
For example, using SHA-256:
echo -n "hello" | sha256sum
The result is:
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
Now change hello to Hello:
echo -n "Hello" | sha256sum
You will get a completely different hash, even though only one character was changed.
Three important properties make hashing useful:
- Same input → same hash: The same data produces the same result when the same hash algorithm is used.
- Small change → big difference: Changing even one character can produce a drastically different hash.
- Fixed length: SHA-256 always produces a 256-bit hash, regardless of whether the input is one word or a large file.
Can You Reverse a Hash?
A cryptographic hash function is designed to be one-way. You can easily calculate a hash from the original data, but you should not be able to practically recover the original data from the hash.
This is because hashing compresses data into a fixed-size value, meaning the original information is not preserved in a reversible form.
However, this does not mean hashes are impossible to guess. An attacker can try possible inputs, hash them, and compare the results. This is why weak passwords can still be discovered.
Why Are Hashes Important?
Hashes are widely used in cybersecurity.
Password protection: Websites should not store your actual password. Instead, they store a securely generated password hash. When you log in, your entered password is processed and compared against the stored value. Modern systems also use techniques such as salting and slow password-hashing algorithms to make guessing attacks more difficult.
File integrity: Hashes can also help verify that a file has not been changed. If a website publishes the expected hash of a download, you can calculate the hash of your copy and compare the two values.
Try It Yourself
If you have Linux, open a terminal and run:
echo -n "hello" | sha256sum
Then change hello to Hello and run the command again.
Notice how dramatically the hash changes.
Note: On macOS, you can use
shasum -a 256instead ofsha256sum.
Key Takeaways
- A hash is a fixed-length representation of data.
- The same input produces the same hash when using the same algorithm.
- A tiny change in the input can produce a completely different hash.
- Cryptographic hashes are designed to be one-way.
- Hashes are commonly used for password protection and file integrity.
- Hashing is different from encryption because encryption is designed to be reversible with the appropriate key.
Next Lesson
Continue with Passwords, Hashing & Salting to learn how hashes are used to protect passwords and why adding a salt makes password attacks harder.
