Что такое хеширование? Полное объяснение хеш-функций
Quick Answer
Hashing конвертирует любой input в output фиксированного размера (hash) через one-way функцию. Одинаковый input всегда даёт одинаковый hash; разные input дают разные hash (collision resistance). Используйте наш бесплатный Hash Generator для SHA-256, SHA-1 и MD5 в браузере.
Introduction
Hashing — процесс конвертации входных данных любого размера в output фиксированного размера, называемый hash или digest. Hash-функция — алгоритм, выполняющий конвертацию. Криптографические hash-функции имеют особые свойства, полезные для целостности данных, хранения паролей и цифровых подписей. В отличие от шифрования, hashing — one-way —нельзя восстановить вход из hash.
Step by Step
-
Understand hash function properties
Cryptographic hash functions have four key properties: (1) Deterministic — same input always gives same output. (2) Quick to compute. (3) One-way — infeasible to recover input from hash. (4) Collision-resistant — infeasible to find two different inputs with the same hash. (5) Avalanche effect — small input change drastically changes output.
-
Learn common algorithms
SHA-256 (256-bit output, 64 hex chars) is the modern standard — used in Bitcoin, TLS, and digital signatures. SHA-512 is more secure but slower. SHA-3 is the newest family. MD5 (128-bit) and SHA-1 (160-bit) are broken for collision resistance and should not be used for security.
-
Distinguish hashing from encryption
Hashing is one-way — you cannot reverse it. Encryption is two-way — you can decrypt with a key. Hashing is for integrity and verification; encryption is for confidentiality. Never use a hash to store data you need to recover.
-
Use hashing correctly
For data integrity, hash the data and compare to a known-good hash. For passwords, use a slow key-stretching hash (bcrypt, scrypt, Argon2) with a unique salt — not raw SHA-256, which is too fast and vulnerable to brute force.
Examples
SHA-256 hash
Input: Hello, World!
Output: dffd6021bb2bd5b0af676290809ec008dfca50a8d29e6ac0a52c2d7e9f0a3b0c
Avalanche effect
Input: Hello, World! (vs Hello, World?)
Output: Completely different hash despite one-character change
MD5 hash (broken, legacy only)
Input: Hello, World!
Output: ed0760733d7505e9ceacf8af225020ac
Common Problems
- Using MD5 or SHA-1 for security —both are broken for collision resistance. Use SHA-256 or stronger for any security purpose.
- Hashing passwords without a salt —identical passwords produce identical hashes, enabling rainbow table attacks. Use bcrypt, scrypt, or Argon2 with a unique salt.
- Confusing hashing with encryption —hashing is one-way (cannot be reversed); encryption is two-way (can be decrypted with a key).
- Expecting hashes to be unique —collisions are theoretically possible but practically infeasible for secure algorithms (SHA-256 has 2^256 possible outputs).
Tips
- Use SHA-256 for data integrity verification, content addressing, and digital signatures.
- For password storage, use bcrypt, scrypt, or Argon2 —not raw SHA-256. These algorithms have key stretching to resist brute force.
- Hashing is one-way —never use it to store data you need to recover. Use encryption for confidential data.
- Use our Hash Generator to compute SHA-256 and other hashes instantly in your browser.