How it works
A hash function such as SHA-256 reads data of any size (a password, a file, a whole disk image) and outputs a fixed-size value: 256 bits for SHA-256, usually written as 64 hexadecimal characters. Change a single letter of the input and the output changes completely. A good hash is one-way, so the input cannot be worked out from the output, and collision-resistant, so in practice nobody can find two inputs that share a hash.
Hashes prove that data has not changed. Download pages publish checksums, Git names every commit by a hash of its contents, build tools put content hashes in file names so browsers can cache them safely, and digital signatures sign a hash rather than the whole file. MD5 and SHA-1 are broken for security use because collisions can be manufactured; SHA-256, SHA-3 and BLAKE3 are the usual choices today.
Hashing is not encryption: there is no key and nothing to decrypt. Fast hashes are also the wrong tool for passwords, which need deliberately slow password hashing.
Hashing vs the alternatives
Related terms
More in Security
Crypto basics