Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteA cryptographic hash function takes an input bit string of any length and produces a fixed-length output called a hash value or digest. It is designed to make it computationally infeasible to find an input matching a chosen digest, find a second input matching a known input’s digest, or find any two different inputs with the same digest. These are distinct security properties, not a guarantee that collisions are mathematically impossible.
What a cryptographic hash function does
NIST defines a cryptographic hash function as a function that maps a bit string of arbitrary length to a fixed-length bit string and is expected to have collision resistance, preimage resistance, and second-preimage resistance. The output is a condensed representation of the input and depends on its contents. See NIST’s cryptographic hash function glossary and its hash function glossary.
As an Amazon Associate I earn from qualifying purchases.
Because the output has a fixed length while inputs can have arbitrary lengths, different inputs must be able to produce the same output in principle. A secure hash is designed to make finding such inputs computationally infeasible; it does not make collisions impossible.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Three security properties, three attacker goals
Preimage resistance
Given a digest, an attacker should find it computationally infeasible to find an input that produces that digest. NIST also calls this the one-way property. This does not mean every hash output is literally impossible to reverse; it describes the expected difficulty of finding a matching input.
#1 Best Overall
Second-preimage resistance
Given a particular input, it should be computationally infeasible to find a different input with the same digest. The attacker is trying to match the hash of a known message.
Collision resistance
It should be computationally infeasible to find any two distinct inputs that produce the same digest. Unlike a second-preimage attack, the attacker is not required to match a specific input chosen in advance. NIST’s hash function glossary distinguishes these goals.
Is SHA-256 a cryptographic hash function?
Yes. SHA-256 is part of the SHA-2 family specified in NIST’s Secure Hash Standard, FIPS 180-4. It produces a 256-bit digest. That output size is not the same as saying every security property provides 256 bits of strength: NIST’s hash-functions guidance says collision-resistance strength is half the output size. For a 256-bit digest, that general estimate is 128 bits for collision resistance. See NIST’s Hash Functions project and its SP 800-107 Rev. 1 guidance.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →NIST also specifies SHA-3 and the SHAKE extendable-output functions in FIPS 202. SHA-2 and SHA-3 are standardized families; the appropriate choice depends on the required security property, output needs, and the standard or protocol an application must follow. FIPS 180-4’s NIST page records a March 7, 2023 planning note that the standard would be revised after two rounds of public comment, so consult that page for its current revision status.
Hashing is not encryption
A hash function produces a digest; hashing alone does not encrypt data or provide a reversible decryption operation. Encryption is intended to protect information so that an authorized party with the appropriate key can recover it. A digest is instead a fixed-length representation used in security mechanisms and protocols. Do not treat a hash as a way to keep a message confidential.
How hashes are used in protocols
Hash functions can represent message contents and serve as components in larger cryptographic algorithms and protocols. One concrete example is Certificate Transparency: IETF RFC 6962 defines a Merkle Tree Hash using SHA-256 and specifies a construction designed to require second-preimage resistance. This illustrates why an application’s required security property matters; the word “hash” alone does not explain the role or guarantees of a particular construction.
Rank #4
What to consider when selecting a hash function
- Security goal: Identify whether the application relies on preimage, second-preimage, or collision resistance.
- Output and strength: Consider both digest length and the security strength associated with the property you need; output length alone is not a complete measure.
- Output format: Determine whether the application needs a fixed-length digest or an extendable-output function such as SHAKE.
- Applicable standard: Follow the specification or protocol requirements relevant to the implementation, including the SHA-2 standard in FIPS 180-4 or SHA-3 and SHAKE in FIPS 202.
Standards and transition guidance can change. For current information about the Secure Hash Standard and NIST’s SHA-1 transition guidance, consult the FIPS 180-4 page and NIST Hash Functions project page.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




