Concept · 8 min read
Hashing vs encryption
Why can a site verify your password but not tell you what it was?
Hashing is one-way fingerprinting; encryption is reversible with a key. Mixing them up causes designs that leak, and reports that overstate or understate risk.
Two different jobs
- Hash: fixed-length digest, no key, not recoverable. Used for verification and integrity.
- Encryption: reversible transform under a key. Confidentiality, with key management as the real problem.
- Encoding (Base64, hex, URL): not protection at all. `echo -n 'x' | base64` is a formatting change.
Why password hashes are slow on purpose
A verification hash must be expensive to try many times. bcrypt, scrypt, Argon2 and PBKDF2 exist for exactly that; MD5/SHA-1/SHA-256 are fast and therefore unsuitable as password storage, which is what makes them crackable at high rates.
text
MD5(password) → billions/sec on one GPU Argon2id(t=3,m=64M) → deliberately memory-hard, thousands/sec at most
Salts, peppers and work factors
- Salt: unique per record, kills rainbow tables and forces per-target work. Must be stored, may be public.
- Pepper: secret mixed in, stored separately from the database. An extra layer, not a substitute for a slow function.
- Work factor: tune upward as hardware improves. That is maintenance, not a one-time setting.
What a hash audit actually measures
When a cracker recovers a password, it is because the guess was in the candidate space — the audit result is a statement about users and policy, and about which lists were covered. '0 recovered' with 10,000 guesses means nothing; say what you tested.
Check your understanding
Answer before expanding. If you cannot explain it in one sentence, the section above needs a re-read.
Is Base64 encryption?Q1
No. It is reversible with no key. 'Encode' and 'encrypt' are not interchangeable words in a design review.
A system stores SHA-256(password + username). Reasonable?Q2
No — fast, and the salt is guessable. Use a memory-hard function with a proper work factor.
Where this shows up
Tools in the directory whose commands assume this knowledge.