What Is a Hash Function? A Plain Guide With Examples

What is a hash function? It is a rule that takes data of any size, from one letter to a whole file, and turns it into a short value of a fixed size, called a hash or a digest. A cryptographic hash function adds a harder promise: nobody can work backward from the digest, or find two inputs that share one. This guide shows both kinds, with a command you can run, and a real hash from a browser tank game that protects nothing.

What is a hash function? The short answer

Wikipedia defines a hash function as any function that maps data of arbitrary size to fixed-size values. Those values are called hash values, hash codes, digests, or simply hashes. The most common everyday use is a hash table, where the hash of a key picks the slot that holds its data.

NIST, the US standards body, is stricter about the cryptographic kind. Its glossary says an approved hash function maps a bit string of any length to a fixed-length bit string, and is expected to have three properties: collision resistance, preimage resistance and second preimage resistance.

So there are two kinds:

  • Ordinary hash functions: fast, and good at spreading values evenly. They power hash tables, error checks and visual patterns. Wikipedia notes that their constructions frequently provide no resistance to a deliberate attack.
  • Cryptographic hash functions: built so that an attacker cannot reverse them or forge a match. This is what security people mean by "a hash."

Try it: hash two words that differ by one letter

Open a terminal on a Mac and run this:

printf 'tank' | shasum -a 256

The SHA-256 digest of tank comes out as:

281a37477f772e7821789956a6de408682d8d2c932ad5a65c485da55c4f83f69

Now change one letter and run printf 'bank' | shasum -a 256. You get:

4381dc2ab14285160c808659aee005d51255add7264b318d07c7417292c7442c

Each digest is 64 hexadecimal characters, which is 256 bits, whatever the input length. The same input always gives the same digest. And one changed letter gives a digest that looks unrelated. Wikipedia calls this the avalanche effect: a small change in the input drastically changes the output.

Use printf, not echo. Plain echo adds a newline, and the newline is part of the input, so you get a different digest.

The three security properties NIST lists

These terms sound alike, so take them one at a time. The wording follows the NIST hash functions page.

Preimage resistance

Given a randomly chosen hash value, it is computationally infeasible to find an input that hashes to it. NIST calls this the one-way property.

Second preimage resistance

Given one input, it is computationally infeasible to find a different input with the same hash. This protects a file you already have: nobody can craft a second file that matches its digest.

Collision resistance

It is computationally infeasible to find any two different inputs with the same hash. NIST says the collision resistance strength in bits is half the output size, while preimage strength equals the output size. For SHA-256, that is 128 bits against collisions and 256 bits against preimages.

Which hash algorithms you will meet

  • MD5: a 128-bit digest. Wikipedia says collisions against MD5 can be calculated within seconds, which makes it unsuitable where a cryptographic hash is required.
  • SHA-1: a 160-bit digest. Collisions can be produced with the attack called SHAttered, and Wikipedia says it should be considered broken. NIST deprecated SHA-1 in 2011 and disallowed it for digital signatures at the end of 2013.
  • SHA-2: the standard FIPS 180-4 specifies SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224 and SHA-512/256.
  • SHA-3: the standard FIPS 202, built on a design called Keccak that came out of a NIST competition. NIST approves its four fixed-length versions as alternatives to the SHA-2 family.

Where cryptographic hashes are used

  • Checking a download: some sites publish a digest next to a file; run shasum -a 256 filename and compare every character. Wikipedia notes this only works if the digest itself comes from a site you trust, usually the original site over HTTPS.
  • Digital signatures: almost all signature schemes hash the message first, then sign the small, fixed-size digest.
  • Passwords: Wikipedia says fast hashes like the SHA series are no longer considered safe for storing passwords, because graphics processors can try billions of guesses a second. It adds that NIST recommends slow functions built for the job, such as PBKDF2, bcrypt, scrypt or Argon2, and that a random salt is stored with each hash.

Hashing vs encryption

Encryption scrambles data so only the holder of the key can read it, and it is built to be undone with that key. A hash has no key and no undo step. For more, read how encryption works: keys and scrambled data.

Why can a hash not be undone? Inputs can be any length, but SHA-256 has a fixed number of possible digests. So many inputs must share each digest, and a digest cannot hold enough to rebuild its input. The only way "back" is to guess inputs, hash them, and compare.

A real hash in Tank City Reboot, and why it is not cryptographic

Tank City Reboot has Encrypted zones. The card says an Encrypted zone "Hides any tank inside it," and adds that "Encrypted data looks like random noise to anyone without the key." To give the zone a noisy look, the drawing code in both games (Art.cs) colors each 2 by 2 pixel block with this line:

int h = ((px >> 1) * 73856093) ^ ((py >> 1) * 19349663);

Here px and py are the pixel position. Shifting right by 1 halves them, so each 2 by 2 group of pixels shares one block. Each half is multiplied by a large number, and ^ (XOR) combines the two. If the last two bits of h are not both 0, the block is light green; if they are, it is dark green.

You can work it by hand:

  1. Pixel (0, 0) is block (0, 0). Both products are 0, so h is 0. Dark green.
  2. Pixel (2, 0) is block (1, 0). h is 73856093. Divided by 4 that leaves 1, so the last two bits are not 0. Light green.
  3. Pixel (0, 2) is block (0, 1). h is 19349663, which leaves 3. Light green.

Here is the catch. The last two bits of a product depend only on the last two bits of the numbers you multiply. So the color depends only on each block's position counted in fours. Exactly one block in four is dark, and the pattern repeats every 8 pixels as diagonal stripes.

Encrypted zone hash pattern of green diagonal stripes beside SHA-256 digests of tank and bank

Left: a 32 by 32 pixel patch colored with the game's exact hash, scaled up with point filtering. Right: SHA-256 of two words one letter apart.

Wikipedia points out that a hash used for spreading values only needs to be uniformly distributed, "not random in any sense." But it is not a cryptographic hash. Given a color, you can list every position that makes it, and finding two positions with the same color is trivial. The hash only picks a shade of green. It protects nothing. For more on how games make values that look random, read how video games make random numbers.

Frequently asked questions

Can two inputs have the same hash?

Yes. Inputs can be any length and digests have a fixed size, so collisions must exist. A cryptographic hash makes them computationally infeasible to find on purpose.

Should I store passwords with plain SHA-256?

No. Wikipedia says fast SHA hashes are no longer considered safe for password storage, and that NIST recommends slow functions instead. Examples are PBKDF2, bcrypt, scrypt and Argon2, each used with a random salt.

Is the hash in Tank City Reboot a cryptographic hash?

No. It is a quick position hash that picks light or dark green for each 2 by 2 block of an Encrypted zone. It protects nothing.

Get started

Tank City Reboot is two free, original tank games that play in your browser, on a computer or a phone. Every enemy, power-up and wall is named for a real computing or security idea, and the game teaches the idea behind each name in one sentence. It is not a security course, and it does not protect your computer. Stage 4, ENCRYPTION, is full of Encrypted zones, so you can spot the stripes yourself, and Tank City Zero Day draws them the same way.

Play Tank City Reboot: it is free, plays in your browser on a computer or a phone, and playing never needs an account.

0 likes

Comments

No comments yet.

Sign in or make an account to comment.