Hash Functions Part 1: Core Properties, Security Requirements and Practical Applications
Hash Functions. Part 1: Fundamentals
Hash function is a function that accepts data of arbitrary length and produces a fixed-length output called a hash or digest. In practice, three core security properties must hold: preimage resistance, second-preimage resistance, and collision resistance. In addition, a good hash function exhibits the avalanche effect: the smallest change in input produces an unrecognizable change in output.
What is a Hash Function?
Preimage resistance means it is computationally infeasible to recover the original input from the digest. Second-preimage resistance means that, given an input and its digest, finding a different input that yields the same digest is practically impossible. Collision resistance means finding any two distinct inputs that produce the same digest is infeasible; neither input is fixed in advance.
Methods for Ensuring Hash Function Security
The theoretical properties have practical limits. Input data must possess sufficient entropy and length; otherwise an attacker can precompute hashes for all possible values and reverse the digest. The output size is equally critical. A minimum digest length of 256 bits is now considered mandatory because it delivers 128 bits of security against collision attacks. A 128-bit digest suffices only for the first two properties, since modern hardware cannot exhaust 2^128 possibilities.
The birthday paradox illustrates why 256 bits are required for collision resistance. The question “How many people must be in a room for a 50 percent chance that at least two share a birthday?” yields the answer 23. Mathematically, when sampling from a space of size 2^N, a collision is expected after roughly 2^(N/2) attempts. Therefore a 256-bit digest is needed to obtain 128-bit collision security. Because of insufficient collision resistance, MD5 and SHA-1 are considered broken.
Hash Functions in Practice
Hashing can be performed directly from the command line with OpenSSL:
echo -n "some words" | openssl dgst -sha256
Any supported algorithm may replace sha256, and a file path may be supplied instead of a string.
Hash functions enable commitment schemes: a party hashes secret data, publishes the digest, and later reveals the original value for verification. The function simultaneously hides the secret and binds the committer to the original data. They also protect web subresource integrity. When loading scripts or stylesheets from a CDN, the integrity attribute allows the browser to verify that the received file matches the expected digest:
<link rel="stylesheet" href="https://my-provider.com" integrity="sha256-HASH_OF_STYLE" crossorigin="anonymous"><script src="https://my-provider.com" integrity="sha256-HASH_OF_SCRIPT" crossorigin="anonymous"></script>
The most widespread use is password storage with memory-hard functions such as Argon2 and bcrypt. Only the digest is stored; when a user supplies a password it is hashed and compared with the stored value. Because the digest itself must be transmitted securely, a hash function alone does not provide integrity; it must be used within a properly designed protocol.
This concludes Part 1. The next installment will examine the internal structure of SHA-2 and SHA-3, their respective strengths and weaknesses, and the appropriate use of XOF functions.
Related articles
Digital Twins Enable Pre-Deployment Testing and Post-Change Control in Complex Multi-Vendor Networks
UserGate and Hadal Project experts presented a joint approach at Saint HighLoad++ that combines physical labs, emulation, and simulation into a single lifecycle for validating network changes. The method addresses recurring failures such as IPsec tunnel outages after routine software updates that pass vendor checks yet break branch connectivity. Three complexity sources—multi-vendor environments, historical configuration debt, and continuous dynamic updates—are mitigated by maintaining an always-current network model. Physical laboratories provide hardware-level accuracy for critical devices, while uInfraTwin emulation allows rapid, repeatable testing of configuration scenarios with traffic generators. Simulation tools including Batfish, Hadal, Forward Networks, and IP Fabric deliver end-to-end reachability analysis across tens of thousands of nodes without sending test traffic on production networks. The integrated digital twin continuously updates from live infrastructure, feeds selected segments into safe test environments, and verifies policy compliance after deployment.
Positive Technologies Releases MaxPatrol SIEM 28.0 with Major Resource Optimizations and AI Enhancements
Positive Technologies has launched MaxPatrol SIEM 28.0, enabling security operations centers to process significantly more security events without requiring additional hardware. Internal tests show the new version consumes up to 26% less CPU and 52% less RAM compared to the previous release. Optimized components for event processing and data storage now allow the system to handle 40,000 events per second instead of 20,000 on comparable servers. The architecture has been refined so that unnecessary roles can be omitted when MaxPatrol SIEM operates independently from other platform products such as MaxPatrol VM. The behavioral analysis module MaxPatrol BAD received the new HackTracker component, which detects attackers by behavior patterns rather than only by tools, and now supports Unix event analysis with linked activity chains. The PT Naira AI assistant has been simplified for easier configuration, helping analysts write normalization rules, explain events, and search documentation, with claims of reducing investigation time by up to 50% and rule creation effort by up to 90%. Analysts also benefit from added context in correlation rule cards, quick navigation links, and a native dark theme.
macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes
A detailed case study describes how a macOS user analyzed Claude application logs after experiencing regional unavailability errors while using WireGuard VPN. The investigation covered ~/Library/Logs/Claude/ files containing markers like app-unavailable-in-region and region_unavailable, cross-referenced with tunnel activity dates from August to October 2026. No direct evidence linked the VPN to the account block, as tunnel logs were overwritten and system journals returned Operation not permitted errors. The user then addressed a secondary issue where WireGuard blocked access to work services including amoCRM, TGBooster, and Geekjob. Custom host routes were added via route add commands to direct specific IPv4 addresses through the local gateway while keeping Claude traffic in the tunnel. A launchd-based PF kill switch was tested for tunnel failure protection but caused a full internet outage on October 5 due to anchor and hook conflicts, leading to its rollback. By October 8, work sites functioned under VPN with verified routes, though persistent kill switch protection remained unresolved.
Publishing Internal APIs from DMZ Without Direct LAN Connections: Five Tested Architectures
When an API gateway resides in the DMZ but security policies forbid outbound connections into the LAN, organizations must adopt alternative patterns to expose internal services synchronously. The article examines five production-ready approaches built on the NEOMSA APIM platform, ranging from custom request-reply logic over Kafka to zero-code solutions using ActiveMQ Artemis and experimental reverse HTTP in HAProxy. Each pattern is evaluated against criteria such as the need for DMZ-to-LAN firewall rules, volume of custom code, support for streaming responses, and measured performance. Load tests on the Artemis-based bridge reached 50 requests per second with a 95th percentile latency of approximately 100 ms, while the Kafka implementation required roughly 2,500 lines of Java to emulate missing reply semantics. The analysis highlights trade-offs in operational complexity, vendor support implications, and security posture, particularly the benefit of preventing any outbound initiation from the DMZ.