Hashing
Hashing is the process of running data through a mathematical algorithm to produce a fixed-length value that represents the original data. This value, often an alphanumeric string of predetermined length, is generally designed to be irreversible, meaning the original data cannot be practically reconstructed from it. In cybersecurity, hashing is commonly used to help protect sensitive information such as passwords, messages, and documents, while in computing more broadly it is also used to store and retrieve data efficiently.
Hashing applies a deterministic mathematical algorithm (a hash function) to input data of arbitrary size to produce a numeric or alphanumeric output of fixed, predetermined length that is representative of that input. Cryptographic hash functions are generally designed to be one-way (irreversible), such that deriving the original input from the output is computationally infeasible; this property underpins their use in protecting sensitive data such as passwords and in verifying data integrity. Note that hashing serves distinct purposes across contexts: in data structures it enables near-constant-time access and reduced storage overhead, whereas in security contexts the emphasis is on irreversibility and collision resistance. Not all hash functions are suitable for security use; non-cryptographic hashes used for indexing or lookup do not provide the same guarantees, and specific algorithm choices and their continued suitability change over time and should be verified against current authoritative guidance.
Why it matters
Hashing is foundational to how organizations protect sensitive information and verify that data has not been altered. In security contexts, storing a hash of a password rather than the password itself means that even if a data store is compromised, an attacker does not directly obtain the original credentials. Because cryptographic hash functions are generally designed to be irreversible, they provide a mechanism for confirming that a value matches a known input without retaining the input in a recoverable form. This distinction matters for compliance programs concerned with data minimization and reducing the impact of a breach.
Hashing also supports data integrity verification: comparing the hash of a received message or document against an expected value can reveal whether the underlying data was changed in transit or at rest. This makes hashing relevant to a range of obligations that touch on the confidentiality and integrity of information. However, it is important not to overstate its protective effect. Hashing is not encryption, and not every hash function is appropriate for security use — non-cryptographic hashes used for indexing or lookup do not provide irreversibility or collision-resistance guarantees. The suitability of specific algorithms also changes over time as cryptanalysis advances.
Because of this, hashing should be treated as one control among several rather than a complete safeguard. Whether a particular hashing approach adequately protects sensitive data is a fact-specific question that depends on the algorithm chosen, how it is implemented, and current authoritative guidance. Organizations should verify their choices against up-to-date standards and recognize that a technique considered sound today may be deprecated in the future.
Who it's relevant to
Inside Hashing
Common questions
Answers to the questions practitioners most commonly ask about Hashing.

