Hash Functions की तुलना: MD5, SHA-1, SHA-256 और CRC32
Hash function मनमाने input को fixed-size fingerprint में निचोड़ देता है: वही file हमेशा वही string देता है, जबकि कोई भी छोटा बदलाव avalanche की तरह बिल्कुल अलग string में बदल जाता है। यही एक गुण तीन बहुत अलग काम करता है — corruption पकड़ना, content की fingerprinting और, अतिरिक्त machinery के साथ, passwords की रक्षा।
1. Files के checksums: MD5, SHA-1, SHA-256
Download pages checksums इसलिए छापते हैं ताकि आप confirm कर सकें कि file सही-सलामत पहुँची: अपनी copy को hash करें और strings मिलाएँ। MD5 सबसे तेज़ है और accidental-corruption जाँच के लिए अब भी ठीक है, SHA-1 बीच में है, और SHA-256 हर अहम चीज़ के लिए मौजूदा default है। Speed का फर्क सिर्फ gigabyte-scale files पर दिखता है।
2. Security के लिए टूटे, integrity के लिए ठीक
MD5 और SHA-1 जानबूझकर हमला करने वालों के सामने चकनाचूर हैं — researchers एक ही MD5 वाली दो अलग files बना सकते हैं, और SHA-1 बरसों पहले practical collision में गिर गया था। इसलिए इन्हें signatures, certificates या password storage के लिए कभी इस्तेमाल न करें; लेकिन आपकी Linux ISO download के अंदर कोई attacker नहीं छिपा है, और शुद्ध corruption detection के लिए वे बिल्कुल अच्छे बने हुए हैं।
3. Passwords को सुस्ती चाहिए, speed नहीं
Fast hashes passwords के लिए गलत औज़ार हैं क्योंकि attackers हर second billions of guesses आज़मा सकते हैं। असली password storage धीमे, salted, memory-hard functions इस्तेमाल करता है जो इसी काम के लिए बने हैं। अगर कोई tutorial आपसे passwords का MD5 store करने को कहे, तो वह tutorial बंद कर दें।
4. CRC32 और HMAC, संक्षेप में
CRC32 cryptographic hash है ही नहीं — यह networking और ZIP files का तेज़ error-detecting code है, transmission glitches पकड़ने में बढ़िया और forgery के सामने बेकार। HMAC, इसके उलट, hash में secret key मिलाता है ताकि पाने वाला integrity और authenticity दोनों verify कर सके। अपने text या files पर यह सब हमारे hash generator से आज़माएँ, जो सब कुछ आपके browser में locally compute करता है।