Hashing: a fingerprint that cannot be reversed
Hashing turns data, whatever its size, into a fixed-length fingerprint. Unlike encryption, this transformation is not meant to be reversible: you do not “unhash” a hash to recover the original data.
Definition
A hash function always produces the same fingerprint for the same input data, but even the smallest change to that data radically changes the resulting fingerprint. This property makes it possible to verify the integrity of a file or message without comparing it in full.
It is also the reference mechanism for password storage: instead of keeping the password in plain text, a service stores its fingerprint, calculated with a dedicated algorithm and a unique salt for each user, to resist dictionary attacks and brute force.
Key points
A one-way transformation
A hash function is not designed to be reversed, unlike encryption.
Verify integrity
Comparing two fingerprints tells you whether a file has been modified without having to read it again in full.
The basis of password storage
A salted hashed password resists database theft far better than a password stored in plain text.
How BCIT can support you
We detail hashing best practices in our article on secure password storage.
Frequently asked questions ❓
Why not simply encrypt passwords?
Because encryption is reversible: if the key is compromised, all passwords are compromised too. Hashing avoids this risk by design.
What is a “salt” in hashing?
A unique random value added to each password before hashing, which prevents precomputed tables from being reused to crack several accounts at once.
Not ready to talk yet? Discover our cybersecurity assessment →
How are your passwords actually stored?
Let’s review together the algorithms and practices used in your applications.
Hashing: a fingerprint that cannot be reversed
Hashing turns data, whatever its size, into a fixed-length fingerprint. Unlike encryption, this transformation is not meant to be reversible: you do not “unhash” a hash to recover the original data.
Definition
A hash function always produces the same fingerprint for the same input data, but even the smallest change to that data radically changes the resulting fingerprint. This property makes it possible to verify the integrity of a file or message without comparing it in full.
It is also the reference mechanism for password storage: instead of keeping the password in plain text, a service stores its fingerprint, calculated with a dedicated algorithm and a unique salt for each user, to resist dictionary attacks and brute force.
Key points
A one-way transformation
A hash function is not designed to be reversed, unlike encryption.
Verify integrity
Comparing two fingerprints tells you whether a file has been modified without having to read it again in full.
The basis of password storage
A salted hashed password resists database theft far better than a password stored in plain text.
How BCIT can support you
We detail hashing best practices in our article on secure password storage.
Frequently asked questions ❓
Why not simply encrypt passwords?
Because encryption is reversible: if the key is compromised, all passwords are compromised too. Hashing avoids this risk by design.
What is a “salt” in hashing?
A unique random value added to each password before hashing, which prevents precomputed tables from being reused to crack several accounts at once.
Not ready to talk yet? Discover our cybersecurity assessment →
How are your passwords actually stored?
Let’s review together the algorithms and practices used in your applications.