Security · Comparison
Hashing vs encryption vs HMAC
Three building blocks that are easy to mix up. Hashing makes a fingerprint, encryption hides data until the right key reveals it, and HMAC proves a message came from someone who holds a shared secret.
3 options · 8 questions side by side · updated
| Compare | Hashing | Encryption | HMAC |
|---|---|---|---|
| What it does | Makes a fixed-size fingerprint of data | Scrambles data so only a key holder can read it | Makes a keyed fingerprint that proves the sender |
| Reversible | No, one-way by design | Yes, with the right key | No, the receiver recomputes and compares |
| Keys needed | None | One shared key, or a public and private pair | One secret shared by sender and receiver |
| Same input, same output | Always | Usually not, a random nonce varies it | Always, for the same key |
| Common algorithms | SHA-256, SHA-3, BLAKE3 | AES-GCM, ChaCha20-Poly1305, RSA, elliptic curves | HMAC-SHA256 |
| Proves | The data has not changed | Only key holders can read it | Unchanged, and sent by a key holder |
| Typical use | Checksums, Git, cache-busting file names | HTTPS, disk and database encryption, chat apps | Webhook signatures, payment callbacks, JWTs |
| Watch out for | Fast hashes are wrong for passwords | Keys stored beside the data they protect | Compare in constant time, reject old timestamps |
How to choose between Hashing, Encryption and HMAC
- Use a hash to check that data has not changed, and a slow password hash such as Argon2id or bcrypt for passwords.
- Use encryption when data must be read again later by someone who holds the key.
- Use HMAC when a receiver must be sure a message came from a partner who shares a secret, as with webhooks and payment callbacks.
The options
- HashingTurning any piece of data into a short, fixed-length fingerprint. The same input always gives the same fingerprint, and the fingerprint cannot be turned back into the data.
- EncryptionScrambling data with a key so that only someone holding the right key can turn it back into something readable.
- HMACA code computed from a message and a shared secret key and sent along with the message, so the receiver can prove it came from someone who knows the secret and was not changed on the way.
More comparisons
- XSS vs CSRF vs SQL injectionThree classic web attacks aimed at different layers. XSS runs an attacker's script inside your pages, CSRF borrows a visitor's signed-in browser, and SQL injection slips commands into your database queries.
- Bug bounty vs penetration testingBoth pay outside experts to find weaknesses before criminals do. A penetration test is a scheduled, scoped engagement that ends in a report; a bug bounty is a standing invitation that pays for each valid finding.
- Node.js vs Deno vs BunThree runtimes for JavaScript and TypeScript on the server. Much of the same code runs on all three; they differ in built-in tools, security defaults, speed and how long each has been used in production.
- Express vs Fastify vs HonoThree JavaScript web frameworks with a similar feel. Express is the long-standing default, Fastify focuses on throughput and structure, and Hono is built on web standards so it can run almost anywhere.
- FastAPI vs Django vs FlaskThree widely used Python web frameworks. Django includes almost everything, Flask includes almost nothing, and FastAPI focuses on typed, self-documenting APIs.
- REST vs GraphQL vs tRPC vs gRPCFour ways for apps and services to ask a backend for data. They differ in who can call them, how strictly the contract is typed, and what travels over the wire.
Crafted in the dark. Shipped to the world.
Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.