Hashing and digital signatures · Hashing y firmas digitales
Hashing protects integrity
- We hashed passwords for secrecy. Hashing also protects integrity — proving data was not changed.
- Change even one character of the input, and the hash changes completely.
Hashing protects integrity
- Hasheamos las contraseñas para garantizar la confidencialidad. El hash también protege la integridad — demostrando que los datos no han sido modificados.
- Cambiar incluso un solo carácter de la entrada hace que el hash cambie completamente.
import hashlib
print(hashlib.sha256(b"hello").hexdigest()[:16])
print(hashlib.sha256(b"hellp").hexdigest()[:16]) # totally different
Checking a download
- Websites publish the hash of a file. After downloading, you hash your copy and compare.
- If the two hashes match, the file arrived intact. If not, it was corrupted or tampered with.
Verificar una descarga
- Los sitios web publican el hash de un archivo. Después de descargarlo, calculas el hash de tu copia y lo comparas.
- Si ambos hashes coinciden, el archivo llegó intacto. De lo contrario, fue corrompido o alterado.
Digital signatures
- A digital signature proves who sent something and that it was not changed.
- The sender hashes the message and encrypts that hash with their private key.
- Anyone can check it with the sender's public key — only the real sender could have made it.
Firmas digitales
- Una firma digital demuestra quién envió algo y que no fue modificado.
- El emisor calcula el hash del mensaje y cifra ese hash con su clave privada.
- Cualquiera puede verificarla con la clave pública del emisor — solo el verdadero emisor podría haberla creado.
Your turn
- Compare the hashes of an original and a received message.
Truemeans the message is intact.
Covers: A-Level 17.1 (digital certification), 6.2 (integrity).
Tu turno
- Compara los hashes de un mensaje original y uno recibido.
Truesignifica que el mensaje está intacto.
Cubre: A-Level 17.1 (certificación digital), 6.2 (integridad).
Common mistakes
- A hash is one-way — you cannot get the original back from it.
- A digital signature proves who sent a message and that it was not changed.
Errores comunes
- Un hash es de una sola vía; no puedes recuperar el original a partir de él.
- Una firma digital demuestra quién envió un mensaje y que este no ha sido modificado.
Hashing & signatures · Hashing y firmas
A hash is one-way and · y avalanches — perfect for fingerprints. · Un hash es de una sola vía y se amplifica — perfecto para huellas dactilares.
Check whether a received message is unchanged. Hash both original and · y received with SHA-256 and print whether the two digests are equal (True or False). · Comprueba si un mensaje recibido está sin cambios. Genera el hash de ambos original y received con SHA-256 y print si los dos resúmenes son iguales (True o False).
Click Run to see the output here. · Haz clic en Ejecutar para ver la salida aquí.
This time an attacker edited the message in transit. Hash both versions and print TAMPERED if the digests differ, else OK — one changed character is enough to catch. · Esta vez, un atacante editó el mensaje en tránsito. Hash ambas versiones e imprime TAMPERED si los digests difieren, de lo contrario OK — basta un solo carácter cambiado para detectarlo.
Click Run to see the output here. · Haz clic en Ejecutar para ver la salida aquí.