What is hashing in cyber security? SHA-256 explained

Hashing gives data a fixed-length fingerprint that can't be reversed. How SHA-256 works, what makes a hash secure, why MD5 and SHA-1 are broken, and hashing leak evidence.

7 min read
On this page 9 sections
  1. What a hash function does
  2. Properties that make a hash secure
  3. SHA-256 in practice
  4. Where hashing is used
  5. Hashing evidence of a leaked lecture
  6. Can you decrypt a hash?
  7. Broken hashes: MD5 and SHA-1
  8. Key takeaways
  9. Frequently asked questions

Hashing turns any input, from a password to a 2 GB lecture file, into a short fixed-length value called a hash or digest, using a one-way function. The same input always produces the same hash, a tiny change produces a completely different one, and you can't work backwards from the hash to the input. In cyber security, hashes are used to prove files haven't been altered, to store passwords safely and as a building block of digital signatures and message authentication.

What a hash function does

Think of a hash as a fingerprint for data. It doesn't contain the data, but it identifies it: if two files have the same SHA-256 hash, you can treat them as identical, and if a single bit differs, the hashes won't match.

SHA-256, the hash you will meet most often, always outputs 256 bits, written as 64 hexadecimal characters, whatever the size of the input. Compare two inputs that differ by one capital letter:

SHA-256("upclass") = 007a42b87aa6409be167a61ac80215e721d6e57efddebd702c3c58009ac7703a
SHA-256("Upclass") = 506c1c464406f15dd43fe3ed0b14c650026b5aacb1e994206290dc3f48e68010

129 of the 256 output bits are different, almost exactly half, which is what you'd expect from two unrelated random values. This "avalanche effect" is deliberate: similar inputs must not produce similar hashes, or attackers could work towards an input step by step.

Properties that make a hash secure

PropertyWhat it meansWhat breaks if it fails
DeterministicThe same input always gives the same hashNothing could be verified
Preimage resistanceGiven a hash, you can't find an input that produces itStored hashes could be turned back into data
Second-preimage resistanceGiven one input, you can't find a different input with the same hashA file could be swapped for a forged one that still matches
Collision resistanceYou can't find any two inputs with the same hashSomeone could get one document signed and pass off another
Avalanche effectA one-bit change flips about half the output bitsHashes would leak how close a guess is

Collision resistance is the first of these to go when a hash weakens, partly because of the birthday effect: among random 256-bit values you expect some pair to match after roughly 2 to the power 128 attempts, not 2 to the power 256. That is why NIST's key-management guidance rates SHA-256 at 128 bits of security where collision resistance is needed, such as digital signatures, and at 256 bits for uses that rely on preimage resistance, such as HMAC.

SHA-256 in practice

SHA-256 belongs to the SHA-2 family, standardised by NIST in FIPS 180-4 (NIST). It pads the input with its length, splits it into 512-bit blocks and runs each block through 64 rounds of mixing, carrying the result forward to the next block. The final state is the hash. SHA-3, standardised in 2015 in FIPS 202, uses a completely different internal design and is a good alternative, though SHA-256 remains the everyday choice.

You can hash a file with built-in tools on every major operating system:

# macOS
shasum -a 256 lecture-14.mp4

# Linux
sha256sum lecture-14.mp4

# Windows PowerShell (SHA-256 is the default)
Get-FileHash .\lecture-14.mp4

One practical trap: when hashing text on the command line, echo 'upclass' adds a newline character, so its hash (0899284931a7...) differs from the hash of upclass alone. Use printf or echo -n when you need an exact match.

Where hashing is used

  • File integrity. Software publishers list SHA-256 values so you can check that a download wasn't corrupted or swapped.

  • Evidence. Hashing a file the moment you capture it lets you show later that it hasn't changed. More on this below.

  • Password storage. Systems store a salted, deliberately slow hash instead of the password. General-purpose hashes like SHA-256 are too fast for this job; see password hashing.

  • Digital signatures. Signing algorithms sign a hash of the document rather than the document itself.

  • Message authentication. An HMAC mixes a secret key into a hash so a receiver can check who sent a message; see how HMAC works.

  • Deduplication and caching. Storage systems and CDNs use hashes to spot identical files and changed content.

Hashing evidence of a leaked lecture

If you find your course on a Telegram channel or a file-sharing site, hashing is how you show that the copy you captured is the copy you present later. A simple routine:

  1. Download the leaked file and compute its SHA-256 hash straight away.

  2. Record the hash with the file name, size, source link, date and time (IST), the device used and the person who captured it.

  3. Store the original in a location that can't be edited, and work only on copies.

  4. Hash the file again whenever it changes hands. Matching hashes show nothing was altered.

This matters in Indian proceedings. The certificate for electronic records in the Schedule to the Bharatiya Sakshya Adhiniyam, 2023 asks for the hash value of the record and the algorithm used, listing SHA1, SHA256, MD5 or another legally acceptable standard (India Code). Prefer SHA-256, for the reasons in the next sections. Our guide to hashing evidence of a leak covers the certificate in detail; this is general information, not legal advice.

Can you decrypt a hash?

No. Hashing isn't encryption, so there is no key to reverse it, and information is genuinely lost: countless inputs map to each hash. What attackers do instead is guess. They hash candidate inputs and compare the results, working through dictionaries of common passwords, every short combination of characters, or tables of hashes computed in advance. Websites that claim to "decrypt SHA-256" or "decrypt MD5" are lookup tables of hashes of common strings.

Guessing works whenever the input is short or predictable, and that catches people out. A 10-digit mobile number has at most ten billion possible values, a trivial number for modern hardware to hash, so a plain SHA-256 of a student's phone number hides almost nothing. If you need to match records without storing the values, use a keyed hash (an HMAC with a secret key kept elsewhere) or tokenisation, compared in encryption vs tokenisation. For passwords, use a salted, slow password hash.

Broken hashes: MD5 and SHA-1

MD5 produces a 128-bit hash. Practical collisions were first shown in 2004, and later research turned them into forged certificates. RFC 6151 (2011) states that MD5 is no longer acceptable where collision resistance is required, such as digital signatures (RFC 6151).

SHA-1 produces a 160-bit hash. In February 2017, researchers from CWI Amsterdam and Google published two different PDF files with the same SHA-1 hash, after roughly nine quintillion SHA-1 computations. In December 2022 NIST announced that SHA-1 should be phased out completely by 31 December 2030 (NIST).

Both are still fine for spotting accidental corruption, and HMACs built on them have not been broken in the same way. But neither should be used for anything new, and neither belongs anywhere near passwords, signatures or evidence you may need to defend.

Key takeaways

  • A hash is a fixed-length fingerprint of data: deterministic, one-way, and completely different after any change.

  • SHA-256 is the everyday standard; SHA-3 is a sound alternative. MD5 and SHA-1 are broken for collisions.

  • Hashes can't be decrypted, but short or predictable inputs such as phone numbers and common passwords can be guessed.

  • Hash leaked files as soon as you capture them, and record SHA-256 values for evidence.

  • Passwords need special slow hashes, and authenticating messages needs a keyed hash (HMAC).

For how hashing compares with the other two ways of transforming data, see encoding vs encryption vs hashing.

Frequently asked questions

Can you decrypt SHA-256?

No. SHA-256 is a one-way hash function, not encryption, so there is no key and no reverse operation. The only way to find what produced a SHA-256 hash is to guess inputs and compare their hashes. That works for short or common inputs, such as popular passwords or phone numbers, which is why "SHA-256 decrypt" sites exist. For long, random inputs, guessing is hopeless.

Can you decrypt a hash?

No hash can be decrypted, because hashing throws information away: a 2 GB file and a single word both become 256 bits, so many inputs share each output. What you can do is try candidate inputs and see whether one produces the same hash. That is how weak passwords are cracked, and why passwords must be stored with salted, deliberately slow hashes rather than fast ones.

Can you decrypt MD5?

No, MD5 is also one-way. Online "MD5 decrypters" are databases of MD5 hashes for common words and passwords, so they only work when the original was guessable. MD5 is broken in a different sense: attackers can deliberately create two different files with the same MD5 hash. Don't use it for passwords, signatures or evidence; use SHA-256 for integrity and Argon2id or bcrypt for passwords.

Share this article

Looking for something else?

Talk to Us