This is the Trace Id: 9ec0941f253233ce5300843a6fd5098e
Skip to main content Microsoft Defender Microsoft Entra Microsoft Intune Project Perception Microsoft Purview Microsoft Sentinel SIEM View all products AI-powered cybersecurity Cloud security Data security & governance Identity & network access Integrated SecOps Security for AI Small and medium business Zero Trust Pricing Services Partners Why Microsoft Security Cybersecurity awareness Customer stories Security 101 Product trials How we protect Microsoft Industry recognition Microsoft Security Insider Microsoft Digital Defense Report Security Response Center Microsoft Security Blog Microsoft Security Events Microsoft Tech Community Documentation Technical Content Library Training & certifications Compliance Program for Microsoft Cloud Microsoft Trust Center Security Engineering Portal Service Trust Portal Microsoft Secure Future Initiative Business Solutions Hub Contact Sales Start free trial Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Software companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap
SECURITY 101

What is hashing in cybersecurity?

Hashing is a fundamental technique used to help verify data integrity and support security practices. It is used in password protection, digital signatures, and blockchain transactions.
Person leaning over a laptop, focused on work.

Hashing is a fundamental concept in cybersecurity that helps verify whether data has changed. Learn how hashing works, why it’s important, and how it differs from encryption.

Key takeaways

  • Hashing converts data into a fixed-length hash value for integrity checks.
  • It is designed to be a one-way process that makes it computationally infeasible to recover the original input from the hash.
  • Common algorithms include SHA-256, SHA-3, and bcrypt for passwords.
  • It’s critical for password storage, digital signatures, and blockchain.
  • Hashing can be used as part of broader security and data protection practices to help support regulatory requirements compliance with the General Data Protection Regulation (GDPR), the Health Insurance Portability and Accountability Act (HIPAA), and the Payment Card Industry Data Security Standard (PCI-DSS).

Hashing definition

Hashing is a way to turn data into a short, unique value called a hash. A hash is a string of characters that represents the original data, much like a digital fingerprint. Change the data, and the fingerprint changes too.

Instead of storing or comparing the original data, systems store the hash and generate a new one when they need to check integrity. This approach sits at the core of the hashing definition and explains why hashes are so useful for security checks.

Hashing is not designed to encrypt data or keep it secret. Its role is narrower and more specific. Hashing provides a reliable way to detect change.

What makes hashing unique

Hashing is a one-way process. Data goes in, a hash comes out, and there is no practical way to reverse the process or recover the original information.

That one-way behavior is what separates hashing from other security techniques. Rather than hiding information, hashing makes unexpected changes easy to spot.

Why hashing matters

Hashing is common in cybersecurity and supports many everyday protections, including:

  • Password storage, where systems store hashed values instead of raw passwords.
  • Digital signatures, which help confirm the authenticity and integrity of documents and messages.
  • File integrity checks, used to detect tampering during storage or transfer.
  • Blockchain technologies, where hashes link records together and expose manipulation.

Hashing also supports essential data protection measures used to safeguard sensitive information across modern environments. These are part of broader information protection fundamentals that help organizations manage risk and protect sensitive systems.

How hashing works

At a high level, hashing follows a simple flow: data goes in, a hash comes out. Behind that simplicity is a carefully designed process that makes hashes reliable for security use.

The basic process

Hashing passes data through a mathematical algorithm called a hash function. That function applies a fixed set of rules to the data and produces a hash, which is the value systems use to represent and verify the original information. This approach is central to ensuring data integrity with hashing.

The basic process follows a simple sequence:

  • Input data: Information such as a password, file, or message is submitted for hashing.
  • Run hash function: A cryptographic algorithm processes the data in a consistent way, regardless of its size or format.
  • Produce hash value: The output is a hash that systems store or compare later to confirm whether the data has changed.

When the same data is passed through the same hash function again, the resulting hash is identical. If the data is altered in any way, the new hash looks completely different, making unexpected changes easy to detect.

For example, if you hash the word Microsoft using a modern hashing algorithm such as SHA-256, the output looks nothing like the original word. The result is a long string of characters that appears random. If you change even one letter, such as microsoft instead of Microsoft, the hash changes entirely.

Core properties that make hashing more secure

Hashing works for cybersecurity because hash functions are designed with specific properties in mind:

  • Deterministic. The same input always produces the same hash, which makes reliable comparison possible.
  • Fixed size output. No matter how large or small the input is, the hash has a predictable length. This makes hashes easy to store, transmit, and compare.
  • Collision resistance. It is extremely difficult to find two different inputs that produce the same hash. This helps protect the integrity of systems that rely on hashing.
  • Avalanche effect. A very small change to the input results in a dramatically different hash. This makes tampering obvious.

Together, these properties allow systems to rely on hashes as accurate representations of whether information is unchanged or has been altered.

Hashing vs. encryption

Hashing and encryption are both used to protect data, but they serve different purposes. Understanding encryption vs. hashing helps clarify why secure systems often rely on both.

What encryption does

Encryption is designed to protect confidentiality. It converts readable data into an unreadable format so it can be stored or shared safely. With the right key, the original data can be recovered. This process depends on the role of cryptographic keys in controlling access to protected data.

Encryption is a two-way process:

  • Data is encrypted to protect it.
  • Authorized users decrypt it to access the original information.

This approach is used when data needs to remain private but still usable, such as emails, files, or messages in transit.

How hashing is different than encryption

Hashing takes a different approach. It does not protect data by hiding it. Instead, it creates a one-way representation of the data that can be used to check integrity.

Key differences include:

  • One-way vs. reversible.Hashing cannot be reversed to reveal the original data. Encryption is designed to be reversed with a key.
  • Integrity vs. confidentiality. Hashing helps confirm data has not changed. Encryption helps keep data private.
  • No key required vs. key-based access. Hashing does not rely on keys. Encryption depends on keys to control access.

Because hashing cannot be undone, it is well suited for scenarios where systems need to verify information without ever storing or exposing it in its original form.

Why secure systems use both

In practice, hashing and encryption are often used together. Each solves a different problem.

For example, when a user signs in, the system does not decrypt a stored password. Instead, it hashes the password entered and compares it to a stored hash. At the same time, encryption may protect the communication channel used during the sign-in process.

Used together, hashing and encryption support layered security. Encryption protects data while it is stored or shared. Hashing helps ensure that data remains accurate and has not been altered along the way.

This distinction is central to understanding modern cybersecurity systems and explains why hash vs. encryption is not an either/or decision. Each plays a specific role in keeping systems secure.

Why is hashing important in cybersecurity?

Hashing plays an important role in maintaining data integrity, securing sensitive information, and supporting trusted systems. It helps ensure that data hasn’t been tampered with, helping reduce the risk of fraud and unauthorized access. Hashing also supports the cybersecurity risk assessment process by making unauthorized changes easier to detect.

Protecting passwords

Instead of storing passwords in plain text, systems store their hash. During login, the system hashes the entered password and compares it to the stored value to authenticate the user. This approach aligns with recommended password security best practices and modern authentication methods in cybersecurity.

Verifying digital signatures

Digital signatures rely on hashing to confirm the authenticity of messages or documents. When a document is signed, its hash is encrypted with a private key. The recipient then hashes the received message and compares the two hashes to ensure no changes were made.

Ensuring data integrity

To maintain the integrity of files or data during storage or transfer, a hash is generated and checked against the original. If the hashes match, the data is intact. If they differ, the data may have been corrupted or tampered with.

Supporting blockchain technology

Blockchain uses hashing to link transaction blocks together. Changing any block would alter the entire chain, which makes tampering immediately detectable and preserves the integrity of the entire system. This visibility supports identifying indicators of compromise in distributed systems.

Meeting compliance standards

For industries governed by regulations like GDPR, HIPAA, and PCI-DSS, hashing can be a safeguard for protecting sensitive data, which helps support compliance requirements. It allows sensitive information to be securely stored while ensuring compliance with privacy standards. These approaches are commonly included in enterprise data security best practices.

Preventing replay attacks and credential theft

To defend against replay attacks, hashes can make stolen data, such as passwords difficult to reuse. These controls also support broader data loss prevention strategies. Techniques like salting—adding a random value to the input before hashing—add an extra layer of protection, making it more difficult for attackers to compromise credentials.

Common types of hashing algorithms

Several hashing algorithms are used in cybersecurity, each with its strengths and weaknesses. Some are designed for speed, while others focus on security. Choosing the right algorithm is crucial for ensuring data remains safe and unaltered.

MD5

Message Digest Algorithm 5 (MD5) was once widely used due to its speed. However, it is now considered weak because it is vulnerable to collision attacks, where two different inputs produce the same hash. As a result, MD5 is no longer recommended for security-critical applications, but it may still be used for tasks like checksums where security isn't the primary concern.

SHA Family

The Secure Hash Algorithm (SHA) family includes several popular algorithms:

  • SHA-1: Once a standard, SHA-1 is now deprecated because it’s vulnerable to collision attacks.
  • SHA-256: Part of the SHA-2 family, SHA-256 offers a higher level of security and is commonly used in digital certificates, blockchain, and password hashing.
  • SHA-3: The latest member of the SHA family, SHA-3 offers similar security to SHA-2 but with a different internal structure. It’s more resistant to certain attack methods and can be used for a variety of applications where SHA-2 is insufficient.

SHA-256 is widely regarded as secure for most use cases and is the preferred option for many systems requiring high security.

Bcrypt and Argon2

Both bcrypt and Argon2 are designed specifically for password hashing. They include features like salting, which adds a random value to each password before hashing. This helps protect against rainbow table attacks, where attackers try to crack password hashes using precomputed lists, and brute-force attacks, which rely on systematically guessing passwords.

By making each hash unique, salting ensures that identical passwords do not produce the same result. This significantly raises the effort required to reverse-engineer stored credentials.

  • Bcrypt: Offers adjustable work factors, allowing organizations to increase hashing difficulty as computing power grows.
  • Argon2: The winner of the Password Hashing Competition (PHC), Argon2 adds memory-hard processing, which requires large amounts of memory to compute and further slows attackers.

Both algorithms are well suited for securely hashing passwords and resisting modern attack techniques.

Performance vs. security trade-offs

When choosing a hashing algorithm, there’s often a trade-off between performance and security. Algorithms like MD5 and SHA-1 may be faster but are no longer suitable for security-critical applications due to vulnerabilities. In contrast, algorithms like SHA-256, bcrypt, and Argon2 are slower but provide significantly stronger protection, making them the better choice for most modern systems.

Real-world use cases

Hashing plays a crucial role in many cybersecurity systems and is used in a variety of ways to protect data and ensure its integrity. Below are some common real-world applications where hashing makes a difference:

Password hashing in web applications

Rather than storing passwords in plain text, systems store their hashes. When users log in, the system hashes the password they enter and compares it to the stored hash. A match means authentication is successful, keeping sensitive data secure even if a database is breached.

Blockchain and cryptocurrency transaction validation

Each block in a blockchain is hashed and linked to the previous one. A change in any block alters its hash, making tampering immediately detectable. This feature ensures the integrity and transparency of cryptocurrency transactions and other blockchain applications.

File integrity checks

Hashing is used in checksums to verify that files haven’t been altered during transfer. For example, when downloading software, the original hash is provided. After the download, the system recalculates the hash and compares it to the original. If the values match, the file is intact. If not, it may have been corrupted.

Digital certificates and secure email communication

Digital certificates rely on hashing to confirm their authenticity. The certificate authority (CA) signs the hash of a certificate. When a user checks the certificate, they hash it again and compare the result to the CA’s signed hash, ensuring secure communication and trust.

API security and token validation

Hashing helps secure APIs by validating access tokens. After a user logs in, the server issues a token containing a hash of the user’s credentials. When the token is used, the system hashes it again and compares the result to the stored value, ensuring the request is valid and untampered.

Cloud storage integrity verification

Cloud providers use hashing to ensure files are not corrupted or altered. When a file is uploaded, the system generates a hash and stores it. When the file is accessed again, the system recalculates its hash and compares it to the original to confirm its integrity.

Best practices for secure hashing

Use strong, modern algorithms

Algorithm choice matters. Some older options are fast, but speed is not a benefit when attackers are trying millions or billions of guesses.

  • For general-purpose integrity checks, use SHA-256 or stronger.
  • For password storage, use algorithms designed for that job, such as bcrypt or Argon2.

Add salt and pepper

Strong algorithms still need the right setup.

  • Salt adds a random value to the input before hashing. This makes each hash unique, even when two users choose the same password. It also makes precomputed attacks, such as rainbow tables, far less effective.
  • Pepper is an additional secret value used during hashing, usually stored separately from the password database. If attackers steal the database, the pepper is not included, which helps limit what they can do with the hashes.

Avoid outdated algorithms

Some hashing algorithms are no longer considered safe for security use because they are vulnerable to collisions and other attacks.

  • Avoid MD5 and SHA-1 for security-sensitive scenarios.
  • Phase them out if they appear in legacy systems.

Use hashing and encryption together

Hashing and encryption serve different purposes. Hashing helps detect unexpected changes. Encryption protects confidentiality. Together, they support layered security, such as encrypted connections that also validate integrity.

Revisit your approach over time

Hashing strategies should not stay static. Over time, computing power grows, best practices evolve, and compliance requirements change.

  • Review hashing settings on a regular cadence.
  • Update password hashing parameters to stay ahead of modern attack speeds.
  • Validate performance under load, especially for authentication systems that need both speed and protection.

Microsoft security solutions

Microsoft offers security tools that use hashing to support data integrity and protect sensitive information across cloud and identity environments. For example, Azure Key Vault relies on hashing as part of its cryptographic operations, helping safeguard keys, secrets, and certificates while supporting secure access controls.

Hashing also plays a role in identity protection solutions such as Microsoft Defender for Identity, where it can help detect suspicious activity tied to credentials and authentication behavior. These capabilities support secure password handling and help organizations identify potential credential-based attacks sooner.

In addition, Microsoft Purview data security solutions use industry standard cryptography to help protect sensitive data across estates. For example, Microsoft Purview Information protection helps classify and protect files and emails using labeling, encryption and access controls.

To learn more about security solutions, explore Microsoft Security, where you’ll find guidance, best practices, and other useful resources.

Frequently asked questions

  • In cybersecurity, hashing is the process of converting data into a fixed-length string of characters called a hash. This hash is unique to the input data, and any changes to the data will result in a different hash. Hashing is commonly used to verify data integrity and store passwords securely without exposing the original data.
  • Hashing and encryption both protect data, but they serve different purposes. Hashing creates a one-way value (hash) for data integrity verification, while encryption transforms data into unreadable format and requires a key to return it to its original form. Encryption protects confidentiality, whereas hashing helps ensure that data hasn’t been altered.
  • The three common types of hashing algorithms are:
    1. MD5: Once popular but now considered insecure due to vulnerabilities.
    2. SHA-2 (including SHA-256): A widely used secure algorithm, often used for integrity checks.
    3. Bcrypt/Argon2: Specialized for password hashing, adding extra protection through salting.
    These algorithms vary in strength and use cases, with some being more secure than others.
  • In cybersecurity, hashing works by applying a hash function to input data, creating a unique output called a hash. This hash is stored or transmitted and can later be compared to a new hash generated from the original data to check for changes. If the hashes match, the data is intact; if not, it has been altered.
  • The most common hashing method is SHA-256. Part of the SHA-2 family, it is widely used in digital certificates, in blockchain, and for securing passwords. SHA-256 offers strong security and is resistant to vulnerabilities found in older algorithms like MD5 and SHA-1.

Follow Microsoft Security

English (United States) Consumer Health Privacy Sitemap Contact Microsoft Privacy Manage cookies Terms of use Trademarks Safety & eco Recycling About our ads