Introduction

At this point, your understanding of encryption is quite robust. You have grasped the concept of public and private keys. You know that they are a form of asymmetric encryption, a method pioneered to improve safe communication and enable encryption and decryption without revealing a private key. You also understand symmetric encryption, an approach that uses one key for encryption and decryption. Though it might not be as secure as asymmetric encryption, it has the advantage of being gentler on computation, and hence good for bulk data encryption that does not need to be sent over a public network. 

In this reading, you will build on this knowledge by exploring hashing. Hashing is very similar to encryption. The two can be confused; however, their execution and purpose are very different. 

Encryption versus hashing

Encryption and hashing both convert data from one form to another but with different purposes and means. While encryption makes data unreadable and requires a key for decryption, hashing converts data into a unique fixed-length value, called a hash, without using keys. The same hash value is produced each time the same text is hashed using the same algorithm. This hash is unique to that document; altering even a single item in the data will cause a different hash to be created. Unlike encrypted data, hashes aren’t meant to be decrypted. Instead, they serve as unique identifiers for data.

Hashing is frequently used in database applications. When hashing is used in a database, a document, or key to a document, is hashed and the number generated determines where that information is stored. It is worth noting that a database is much like a dictionary. The key is used to find the definition. The word and definition are always the same. Applying a hash creates a unique hash which indicates where in the database the information is stored. This key is not secret and it is used for easy storage and look up. An encryption key is different in that it translates a text to make it unreadable. Hashing is a process commonly used to validate a user’s password, it is not a safeguard to protect privacy like encryption. 

While encryption and hashing are very similar, there are some distinctions: 

  • One-way versus reversible: Hashing is strictly a one-way process. Once the hash is created, it cannot be reversed. This contrasts with encryption, which can be reversed to return the original content. 
  • Authenticity versus communication: Hashing verifies that the data remains as originally intended. Encryption ensures confidentiality. 
  • Fixed output versus variable length: A hash will always output a fixed-length output. Depending on the approach used, a cipher can be fixed or variable in length. 

Hashing algorithms and salting

Hashing algorithms are very common and universally known. This is to say that a hashing algorithm is deterministic. A deterministic function is one that always generates the same result. This leaves room for a hacker to use a dictionary attack, where they find hashes of common passwords and attempt to use them to gain access. To prevent this, an extra layer of security is added to a database through a process called salting. This refers to adding a fixed-length random value to the input of hash functions before they are processed to create unique hashes for the same input. The resulting output will not be the same as an unsalted hash. The net result of salting is that it’s more difficult for hackers to “guess” the hash because they don’t know what salting value was used. 

Hashing in cybersecurity

Hashing is used in many areas to bolster cybersecurity: 

  • Password storage: Some companies increase customer protection by retaining a hash of a password rather than the password. Recall that hashing is deterministic, so the hash will always match when a user enters their password. A hash is also one-way. So, if a hacker gains access to a system, all they will gain is the hash of the password, not the password itself. 
  • Digital signature: A digital signature is a method used to verify the authenticity and integrity of a message or document, and it uses a combination of hashing and encryption. First, the message or document is hashed, resulting in a unique hash. This hash is then encrypted with the sender’s private key to create the digital signature. Together, the original document and its digital signature are sent. Upon receipt, the recipient hashes the document anew and decrypts the signature using the sender’s public key to get an original hash. If the recipient’s hash matches the decrypted one, the content remains unaltered since dispatch. Any discrepancy indicates tampering during transmission.
  • Digital forensics: Hashing is an effective way to monitor and verify the integrity of programs and files on your computer. By generating a hash of stored files, you create a unique fingerprint or signature of that file. In the event of a security breach or incident, a fresh scan of your files can be done, and the results can be compared with the stored result to identify any alterations. This is a variation of malware detection. By maintaining a database of known malware hashes, a system can be scanned to detect files matching these known malicious signatures, thereby highlighting potential threats.

Conclusion

In the digital age, ensuring the security and integrity of information has never been more crucial. Hashing and encryption are two powerful tools in a cyber specialist’s arsenal. They play different roles, but both are very concerned with the safe transmission, receipt, and storage of data. Encryption provides a means to keep data confidential, allowing only authorized individuals to access the true content. On the other hand, hashing plays an essential role in verifying that data remains unaltered and authentic. Together, these tools form the bedrock of modern digital interactions, safeguarding information and assets. In the upcoming video, you will examine some algorithms in detail.