การแฮชคืออะไร? คำอธิบายฉบับสมบูรณ์ของฟังก์ชันแฮช
Quick Answer
Hashing แปลง input ใดๆ เป็น output ขนาดคงที่ (hash) ด้วยฟังก์ชัน one-way input เดียวกันได้ hash เดียวกัน; input ต่างกันได้ hash ต่างกัน (collision resistance) ใช้ Hash Generator ฟรีของเราเพื่อ SHA-256, SHA-1, MD5 ในเบราว์เซอร์
Introduction
Hashing คือกระบวนการแปลง input ขนาดใดๆ เป็น output ขนาดคงที่เรียก hash หรือ digest ฟังก์ชัน hash คือ algorithm ที่ทำการแปลง ฟังก์ชัน hash cryptography มีคุณสมบัติพิเศษสำหรับ integrity เก็บพาสเวิร์ด และ signature ต่างจาก encryption hashing เป็น one-way —ย้อนกลับไม่ได้
Step by Step
-
Understand hash function properties
Cryptographic hash functions have four key properties: (1) Deterministic — same input always gives same output. (2) Quick to compute. (3) One-way — infeasible to recover input from hash. (4) Collision-resistant — infeasible to find two different inputs with the same hash. (5) Avalanche effect — small input change drastically changes output.
-
Learn common algorithms
SHA-256 (256-bit output, 64 hex chars) is the modern standard — used in Bitcoin, TLS, and digital signatures. SHA-512 is more secure but slower. SHA-3 is the newest family. MD5 (128-bit) and SHA-1 (160-bit) are broken for collision resistance and should not be used for security.
-
Distinguish hashing from encryption
Hashing is one-way — you cannot reverse it. Encryption is two-way — you can decrypt with a key. Hashing is for integrity and verification; encryption is for confidentiality. Never use a hash to store data you need to recover.
-
Use hashing correctly
For data integrity, hash the data and compare to a known-good hash. For passwords, use a slow key-stretching hash (bcrypt, scrypt, Argon2) with a unique salt — not raw SHA-256, which is too fast and vulnerable to brute force.
Examples
SHA-256 hash
Input: Hello, World!
Output: dffd6021bb2bd5b0af676290809ec008dfca50a8d29e6ac0a52c2d7e9f0a3b0c
Avalanche effect
Input: Hello, World! (vs Hello, World?)
Output: Completely different hash despite one-character change
MD5 hash (broken, legacy only)
Input: Hello, World!
Output: ed0760733d7505e9ceacf8af225020ac
Common Problems
- Using MD5 or SHA-1 for security —both are broken for collision resistance. Use SHA-256 or stronger for any security purpose.
- Hashing passwords without a salt —identical passwords produce identical hashes, enabling rainbow table attacks. Use bcrypt, scrypt, or Argon2 with a unique salt.
- Confusing hashing with encryption —hashing is one-way (cannot be reversed); encryption is two-way (can be decrypted with a key).
- Expecting hashes to be unique —collisions are theoretically possible but practically infeasible for secure algorithms (SHA-256 has 2^256 possible outputs).
Tips
- Use SHA-256 for data integrity verification, content addressing, and digital signatures.
- For password storage, use bcrypt, scrypt, or Argon2 —not raw SHA-256. These algorithms have key stretching to resist brute force.
- Hashing is one-way —never use it to store data you need to recover. Use encryption for confidential data.
- Use our Hash Generator to compute SHA-256 and other hashes instantly in your browser.