Hashing vs Encryption: What’s the Difference?

Encryption is reversible: data is scrambled with a key and can be unscrambled with a key, so it protects confidentiality. Hashing is one-way: data is mapped to a fixed-size digest that cannot be turned back into the input, so it protects integrity and fingerprints data. Encrypt when something must be read again later; hash when you only need to verify or compare. Using one where the other belongs — hashing data you must recover, encrypting a password — is a classic mistake.

Encryption
Reversible with a key — confidentiality
Hashing
One-way, keyless — integrity, fingerprint
Rule
Recover later → encrypt; verify only → hash

Reversible versus one-way

The deciding question is whether you ever need the original back. A message the recipient must read is encrypted, because it has to be decryptable. A password you only ever need to check is hashed, because you should never be able to recover it — if your store leaks, hashes protect the users where decryptable secrets would not.

They often appear together: a signature hashes a document and encrypts (signs) the hash; a sealed record hashes its bytes for an identity anyone can recompute. Knowing which tool does which is the difference between a system that protects data and one that only looks like it does.

Related standards

NIST FIPS 180-4 — Secure Hash Standard

Questions

Can you decrypt a hash?

No — hashing is one-way by design. You can only compare a new hash to a stored one, not reverse it.

Should passwords be encrypted or hashed?

Hashed (with a salt and a slow algorithm). Encrypted passwords can be decrypted if the key leaks; hashed ones cannot be recovered.

Keep reading

related
What Is a Cryptographic Hash Function?
related
Symmetric vs Asymmetric Encryption: What’s the Difference?
related
What Is a Merkle Tree?
related
What Is Content Addressing?
Trust & the Record
Verify, Don’t Trust: Verification for AI Agents
Trust & the Record
Provenance for Autonomous Actions
Trust & the Record
How Is AI Agent Reputation Earned and Verified?
Trust & the Record
Zero-Trust Architecture for AI Agents
Trust & the Record
What Is Agent Attestation?
Trust & the Record
What Is a Trust Graph for Agents?
Trust & the Record
What Is a Zero-Knowledge Proof?
Trust & the Record
What Is a zk-Rollup?
Trust & the Record
What Is a Blockchain Oracle?
Trust & the Record
What Is Confidential Computing?
Trust & the Record
zk-Rollup vs Optimistic Rollup: What’s the Difference?
Trust & the Record
TEEs vs Zero-Knowledge Proofs: Two Roads to Privacy
Trust & the Record
What Is Public-Key Cryptography?
Trust & the Record
What Is a Digital Signature?
Trust & the Record
What Is Mutual TLS (mTLS)?
Trust & the Record
What Is a Sybil Attack?
Trust & the Record
What Is Certificate Transparency?

By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.