(w)Hashing Machine
Hash functions
Introduction
In the context of data confidentiality in computing, the term "encryption" is often used to indicate the process of modifying an object to be kept secret using an algorithm and an encoding key. However, hash functions provide a similar effect through a different process.
Operation
Hash functions are functions that take variable-length input messages and produce fixed-length output.
h = H(m)
- m: input message of any size
- h: fixed-length output
- The output h is called "message digest" (digest).
In addition to these properties, it is important to note an extremely important rule for its proper operation:
Every different input generates a different output, even if only one bit of input changes. The transformation is unique, so there is no way to trace back to the input from the generated digest.
Advantages
The computational cost for hashing is much lower compared to encrypting the message. This makes the use of hash functions more efficient if the goal is the same.
For example, hash functions are commonly used for password storage in databases. During a login attempt with credentials (e.g., user/password), the password comparison is not done in plaintext. Instead, the entered password in the login form is hashed, and it is compared with the hashed password stored in the database.
The only way for the two digests to match is if the input data is equivalent. Thus, this allows us to check user passwords, ensuring the confidentiality of their data while making the verification code efficient.
Hash functions are used in many other computing processes, including Digital Signatures. The fundamental concept is always the verification of digests to ensure integrity and/or congruence of messages; this can be useful when searching for malware by checking if they correspond to hashes of known malicious executables.
Achilles' Heel
The fundamental concept behind hash functions is that the process is completely unique. In other words, if the algorithm is valid, the result will always be the same. However, over the years, a vast database has emerged containing "digests" of various words, allowing malicious users to trace back to hashed passwords if the corresponding record is present in such databases.
An example of a site that allows you to verify hashes generated by common algorithms is Crack Station. This phenomenon emphasizes the importance of keeping passwords up to date. It is crucial to avoid weak choices like "password123" since such strings are often included in common password lists used by attackers.
Fortunately, there is a countermeasure to address this vulnerability: the implementation of the "salt" technique. The salt is a variable-length string added to the string being hashed. This strategy allows for the generation of an extremely high number of combinations, making it impractical to attempt calculating all possible variants. So, just as in preparing a plate of pasta, even in using hash functions, it is essential to remember to add the right "salt" for robust security. 🧂
Example of Salt in Laravel
In Laravel, when using the Hash::make($password) function, the framework automatically generates a random salt and incorporates it into the hash result. However, the salt is not stored separately from the hash result. Instead, it is included in the hash result itself.
The format of the hash result produced by Laravel using Bcrypt includes both the salt and the hash value. For example:
$2y$10$VJfTnrSmSdqXW8yN9rPZZeMUcYP.aYklAQ.OCPEOec4TkU8k/D13a
$2y$10$ indicates the Bcrypt algorithm and the calculation cost (10 is the default cost in Laravel). VJfTnrSmSdqXW8yN9rPZZe is the salt, and MUcYP.aYklAQ.OCPEOec4TkU8k/D13a is the hash result.
The salt is integrated into the hash result, and during the password verification (using Hash::check($input_password, $stored_hash)), Laravel automatically extracts the salt from the hash result to perform the correct verification.
Common Hashing Algorithms
- MD5 (Message Digest Algorithm 5):
- Commonly used for checksums and integrity verification.
- Produces a 128-bit (32-character) hash value.
- SHA-1 (Secure Hash Algorithm 1):
- Originally designed for cryptographic security.
- Produces a 160-bit (40-character) hash value.
- Deprecated for security-sensitive applications due to vulnerabilities.
- SHA-256 (Secure Hash Algorithm 256-bit):
- Part of the SHA-2 family.
- Produces a 256-bit (64-character) hash value.
- Widely used in blockchain technology and other security applications.
- SHA-3 (Secure Hash Algorithm 3):
- The latest member of the Secure Hash Algorithm family.
- Provides the same hash lengths as SHA-2 (224, 256, 384, 512 bits).
- Designed to be more secure against certain types of attacks.