hashing.md (19471B)
1 --- 2 title: "Hashing & Hash Identification" 3 description: "Compute and identify hashes (md5/sha/NTLM), encodings, and pick the right cracking mode." 4 category: cryptography 5 tags: [cryptography, hashing, identification] 6 tools: [hashid, hash-identifier, openssl] 7 difficulty: beginner 8 updated: "2026-08-09" 9 source: "vault:HashingAndEncrypting/Hashing cheat sheet .md" 10 --- 11 12 # Hashing & Hash Identification 13 14 CLI tools only, no Python scripts. 15 16 > Covers: `sha*sum` · `md5sum` · `b2sum` · `openssl dgst` · `openssl kdf` · `argon2` · `htpasswd` (bcrypt) · `john` · `hashcat` · `openssl rand` · `pwgen` · `/dev/urandom` 17 18 ## Table of Contents 19 20 1. [Generating Secure Passwords & Random Data](#1-generating-secure-passwords--random-data) 21 2. [SHA Family](#2-sha-family) 22 3. [MD5](#3-md5) 23 4. [BLAKE2](#4-blake2) 24 5. [OpenSSL — All-in-One Digests](#5-openssl--all-in-one-digests) 25 6. [PBKDF2 via OpenSSL](#6-pbkdf2-via-openssl) 26 7. [scrypt via OpenSSL](#7-scrypt-via-openssl) 27 8. [Argon2 CLI](#8-argon2-cli) 28 9. [bcrypt via htpasswd](#9-bcrypt-via-htpasswd) 29 10. [Comparing & Verifying Hashes](#10-comparing--verifying-hashes) 30 11. [Cracking — hashcat & john](#11-cracking--hashcat--john) 31 12. [Quick Reference Table](#12-quick-reference-table) 32 13. [Which Algorithm Should I Use?](#13-which-algorithm-should-i-use) 33 34 --- 35 36 ## 1. Generating Secure Passwords & Random Data 37 38 All entropy sources below read from the kernel's CSPRNG (`/dev/urandom` on Linux, `getentropy()` on modern systems). These are cryptographically secure — suitable for tokens, API keys, salts, and passphrases. 39 40 ### openssl rand — the go-to tool 41 42 `openssl rand` is available everywhere OpenSSL is installed and is the simplest way to generate raw random bytes in hex or base64. 43 44 ```bash 45 # 32 random bytes as hex (64 hex chars — good for tokens/API keys) 46 openssl rand -hex 32 47 48 # 32 random bytes as base64 (~44 chars) 49 openssl rand -base64 32 50 51 # 16 bytes as base64 (compact token, ~24 chars) 52 openssl rand -base64 16 53 54 # 64 bytes as base64 (long-form secret key) 55 openssl rand -base64 64 56 57 # Raw binary (pipe into xxd for inspection) 58 openssl rand 16 | xxd 59 60 # Strip base64 padding and newline (clean single-line output) 61 openssl rand -base64 32 | tr -d '=\n' 62 63 # URL-safe base64 (replace +/ with -_) 64 openssl rand -base64 32 | tr '+/' '-_' | tr -d '=\n' 65 ``` 66 67 ### /dev/urandom — low-level, no dependencies 68 69 Direct reads from the kernel CSPRNG. Useful in minimal environments or scripts where you need precise character filtering. 70 71 ```bash 72 # 20 alphanumeric characters 73 cat /dev/urandom | tr -dc 'a-zA-Z0-9' | head -c 20; echo 74 75 # 32-char password with symbols 76 cat /dev/urandom | tr -dc 'a-zA-Z0-9!@#$%^&*()-_=+' | head -c 32; echo 77 78 # Lowercase hex (like a short UUID fragment) 79 cat /dev/urandom | tr -dc '0-9a-f' | head -c 32; echo 80 81 # 5-word passphrase from the system dictionary (diceware-style) 82 shuf -n 5 /usr/share/dict/words | tr '\n' '-' | sed 's/-$/\n/' 83 84 # Generate a random salt (16 bytes hex) for use with argon2/scrypt 85 cat /dev/urandom | head -c 16 | xxd -p | tr -d '\n'; echo 86 ``` 87 88 ### gpg --gen-random — NIST-quality randomness 89 90 `gpg` exposes three "quality levels" of randomness. Level 1 uses `/dev/urandom`, level 2 uses `/dev/random` (may block), level 0 is pseudo-random. 91 92 ```bash 93 # 20 bytes of strong random data as base64 (quality level 1) 94 gpg --gen-random 1 20 | base64 95 96 # 32 bytes (quality level 2 — strongest, may block waiting for entropy) 97 gpg --gen-random 2 32 | base64 98 99 # Hex output via xxd 100 gpg --gen-random 1 16 | xxd -p | tr -d '\n'; echo 101 ``` 102 103 ### pwgen — human-memorable passwords 104 105 `pwgen` is purpose-built for generating pronounceable, human-friendly passwords. 106 107 ```bash 108 # Install 109 sudo apt install pwgen # Debian/Ubuntu 110 sudo dnf install pwgen # Fedora/RHEL 111 brew install pwgen # macOS 112 113 # 20-character password, 1 result 114 pwgen 20 1 115 116 # 32-character, fully random (not pronounceable), 1 result 117 pwgen -s 32 1 118 119 # Include at least 1 capital, 1 number, 1 symbol 120 pwgen -cnys 20 1 121 122 # Generate 10 passwords of length 16 123 pwgen 16 10 124 125 # No vowels (avoids accidental rude words — useful for generated usernames) 126 pwgen -v 12 5 127 ``` 128 129 | Flag | Meaning | 130 |---|---| 131 | `-s` | Fully random (not pronounceable) | 132 | `-c` | Include uppercase | 133 | `-n` | Include numbers | 134 | `-y` | Include symbols | 135 | `-v` | No vowels | 136 | `-B` | Avoid ambiguous chars (0/O, 1/l/I) | 137 138 ### apg — advanced password generator 139 140 `apg` generates pronounceable or random passwords with fine-grained rules. 141 142 ```bash 143 # Install 144 sudo apt install apg 145 146 # 6 pronounceable passwords of length 12 147 apg -n 6 -m 12 148 149 # Random passwords (not pronounceable), length 20 150 apg -a 1 -n 5 -m 20 -M SNCL # S=symbols N=numbers C=caps L=lowercase 151 152 # Exclude ambiguous characters (no 0/O/l/1) 153 apg -a 1 -n 3 -m 16 -E 0O1lI 154 ``` 155 156 ### Diceware / EFF wordlist passphrase 157 158 A proper diceware passphrase from the EFF large wordlist gives ~12.9 bits of entropy per word. 6 words = ~77 bits — stronger than most random passwords. 159 160 ```bash 161 # Download the EFF large wordlist (one-time) 162 curl -sO https://www.eff.org/files/2016/07/18/eff_large_wordlist.txt 163 164 # Simulate 5 dice rolls and look up words (manual diceware) 165 for i in {1..5}; do 166 roll=$(( ( RANDOM % 6 + 1 ) * 10000 + ( RANDOM % 6 + 1 ) * 1000 + \ 167 ( RANDOM % 6 + 1 ) * 100 + ( RANDOM % 6 + 1 ) * 10 + \ 168 ( RANDOM % 6 + 1 ) )) 169 grep "^${roll}" eff_large_wordlist.txt | awk '{print $2}' 170 done | tr '\n' '-' | sed 's/-$/\n/' 171 172 # Alternatively: pick 6 random words from the system dictionary 173 shuf -n 6 /usr/share/dict/words | paste -sd '-' 174 ``` 175 176 ### Quick comparison — which generator to use? 177 178 | Tool | Best for | Entropy source | Notes | 179 |---|---|---|---| 180 | `openssl rand` | Tokens, API keys, salts | CSPRNG | Available everywhere | 181 | `/dev/urandom` | Scripting, custom charsets | Kernel CSPRNG | Filter with `tr` | 182 | `gpg --gen-random` | Highest-quality randomness | `/dev/random` | May block | 183 | `pwgen` | Human-typed passwords | CSPRNG | Pronounceable option | 184 | `apg` | Policy-enforced passwords | CSPRNG | Fine-grained rules | 185 | Diceware | Memorable passphrases | Physical dice / RANDOM | Highest memorability | 186 187 > **OPSEC —** `openssl rand -base64 32 | tr -d '=\n'` is the one-liner to remember. It works on every system with OpenSSL, outputs URL-safe-ish base64, and requires zero extra packages. Use it for salts, CSRF tokens, session secrets, and API keys. 188 189 --- 190 191 ## 2. SHA Family 192 193 The `sha*sum` utilities ship with every Linux distro (`coreutils`). They're fast, UNIX-native, and output `<hash> <filename>` or `<hash> -` when reading from stdin. 194 195 ### Hash a string 196 197 ```bash 198 # SHA-256 199 echo -n "Password123" | sha256sum 200 # -n strips the trailing newline — ALWAYS use it, or your hash will be wrong 201 202 # SHA-512 203 echo -n "Password123" | sha512sum 204 205 # SHA-1 (legacy — avoid for passwords) 206 echo -n "Password123" | sha1sum 207 208 # SHA-224 / SHA-384 209 echo -n "Password123" | sha224sum 210 echo -n "Password123" | sha384sum 211 ``` 212 213 ### Hash a file 214 215 ```bash 216 sha256sum /etc/passwd 217 sha512sum secret.txt 218 ``` 219 220 ### Strip the filename from output (hash only) 221 222 ```bash 223 echo -n "Password123" | sha256sum | cut -d' ' -f1 224 ``` 225 226 ### Verify a file against a known hash 227 228 ```bash 229 # Create a checksum file 230 sha256sum important.iso > important.iso.sha256 231 232 # Verify later 233 sha256sum -c important.iso.sha256 234 # Output: important.iso: OK 235 ``` 236 237 ### Hash multiple files at once 238 239 ```bash 240 sha256sum file1.txt file2.txt file3.txt > checksums.txt 241 sha256sum -c checksums.txt 242 ``` 243 244 > **Note —** SHA-256/512 are **cryptographic digests**, not password hashing functions. They have no salt and no work factor — never store passwords with them directly. 245 246 --- 247 248 ## 3. MD5 249 250 ```bash 251 # Hash a string 252 echo -n "Password123" | md5sum 253 254 # Hash a file 255 md5sum /etc/shadow 256 257 # macOS equivalent (if you're on a Mac) 258 md5 -s "Password123" 259 md5 /etc/shadow 260 ``` 261 262 > **Warning —** MD5 is **broken** for security purposes. Collisions are trivially found. Use it only for file integrity checks where you trust the source. Never for passwords. 263 264 --- 265 266 ## 4. BLAKE2 267 268 BLAKE2 is faster than SHA-3 and SHA-2, still cryptographically secure, and built into modern Linux (`coreutils >= 8.25`). 269 270 ```bash 271 # BLAKE2b-512 (default b2sum) 272 echo -n "Password123" | b2sum 273 274 # Hash a file 275 b2sum firmware.bin 276 277 # BLAKE2s-256 — use openssl for this variant (see section 5) 278 openssl dgst -blake2s256 firmware.bin 279 ``` 280 281 --- 282 283 ## 5. OpenSSL — All-in-One Digests 284 285 `openssl dgst` supports every digest OpenSSL knows about. Useful when you need a specific algorithm not covered by `*sum` tools. 286 287 ### Basic usage 288 289 ```bash 290 openssl dgst -sha256 file.txt 291 openssl dgst -sha512 file.txt 292 openssl dgst -sha3-256 file.txt 293 openssl dgst -sha3-512 file.txt 294 openssl dgst -blake2b512 file.txt 295 openssl dgst -blake2s256 file.txt 296 openssl dgst -sm3 file.txt # Chinese national standard 297 ``` 298 299 ### Hash a string (no file) 300 301 ```bash 302 echo -n "Password123" | openssl dgst -sha256 303 echo -n "Password123" | openssl dgst -sha3-512 304 ``` 305 306 ### Output raw hex only (no label) 307 308 ```bash 309 echo -n "Password123" | openssl dgst -sha256 | awk '{print $2}' 310 ``` 311 312 ### HMAC (keyed hash — authentication) 313 314 ```bash 315 echo -n "message" | openssl dgst -sha256 -hmac "supersecretkey" 316 ``` 317 318 ### List all available digest algorithms 319 320 ```bash 321 openssl list -digest-commands 322 openssl list -digest-algorithms # more complete list 323 ``` 324 325 --- 326 327 ## 6. PBKDF2 via OpenSSL 328 329 PBKDF2 (Password-Based Key Derivation Function 2) is a proper password KDF — it adds salt and stretching via a configurable iteration count. Used in WPA2-PSK, LUKS, iOS keychain, and many more. 330 331 ```bash 332 # Basic: PBKDF2-HMAC-SHA256, 100000 iterations, 32-byte key 333 echo -n "Password123" | openssl kdf \ 334 -kdfopt digest:SHA256 \ 335 -kdfopt pass:Password123 \ 336 -kdfopt salt:$(openssl rand -hex 16) \ 337 -kdfopt iter:100000 \ 338 -keylen 32 \ 339 PBKDF2 340 341 # With a fixed known salt (for reproducibility in testing) 342 openssl kdf \ 343 -kdfopt digest:SHA256 \ 344 -kdfopt pass:Password123 \ 345 -kdfopt salt:deadbeefcafe1234 \ 346 -kdfopt iter:600000 \ 347 -keylen 32 \ 348 PBKDF2 349 ``` 350 351 ### PBKDF2 the classic way (enc -pbkdf2, outputs base64-wrapped) 352 353 ```bash 354 # Encrypt (also derives a key from the password using PBKDF2) 355 echo "secret data" | openssl enc -aes-256-cbc -pbkdf2 -iter 600000 -pass pass:Password123 | base64 356 357 # The openssl enc route is more for encryption than storing a password hash, 358 # but it demonstrates PBKDF2 key derivation in action. 359 ``` 360 361 > **Recommended iterations (2024):** 600,000+ for SHA-256, 210,000 for SHA-512 (OWASP). 362 363 --- 364 365 ## 7. scrypt via OpenSSL 366 367 scrypt is a memory-hard KDF. It's deliberately expensive in both CPU **and** RAM, making GPU/ASIC attacks much harder. Used in Litecoin, LUKS2, and many modern password stores. 368 369 ### Parameters 370 371 | Param | Meaning | Typical value | 372 |---|---|---| 373 | `N` (cpu-count) | CPU/memory cost (must be power of 2) | 32768–1048576 | 374 | `r` (block-size) | Block size | 8 | 375 | `p` (parallel) | Parallelisation | 1 | 376 377 Memory used ≈ `128 × N × r` bytes. At N=32768, r=8: ~32 MB. 378 379 ```bash 380 # Generate a scrypt-derived key (32 bytes) 381 openssl kdf \ 382 -kdfopt pass:Password123 \ 383 -kdfopt salt:$(openssl rand -hex 16) \ 384 -kdfopt n:32768 \ 385 -kdfopt r:8 \ 386 -kdfopt p:1 \ 387 -keylen 32 \ 388 scrypt 389 390 # Higher security (128 MB RAM, slower) 391 openssl kdf \ 392 -kdfopt pass:Password123 \ 393 -kdfopt salt:randomsalthere \ 394 -kdfopt n:1048576 \ 395 -kdfopt r:8 \ 396 -kdfopt p:1 \ 397 -keylen 64 \ 398 scrypt 399 ``` 400 401 > **Tip —** Always generate a random salt per-password with `openssl rand -hex 16` and store it alongside the hash. Without the salt you can't re-derive the hash. 402 403 --- 404 405 ## 8. Argon2 CLI 406 407 Argon2 is the **winner of the 2015 Password Hashing Competition** and the current gold standard for password hashing. Three variants: 408 409 | Variant | Use case | 410 |---|---| 411 | `argon2d` | GPU-resistance, not side-channel safe | 412 | `argon2i` | Side-channel safe (filling stations, enclaves) | 413 | `argon2id` | Hybrid — **recommended for general use** | 414 415 ### Install 416 417 ```bash 418 # Debian/Ubuntu 419 sudo apt install argon2 420 421 # Fedora/RHEL 422 sudo dnf install argon2 423 424 # Arch 425 sudo pacman -S argon2 426 427 # macOS 428 brew install argon2 429 ``` 430 431 ### Basic usage 432 433 ```bash 434 # Hash using argon2id (recommended) 435 echo -n "Password123" | argon2 "somesalt16bytes!" -id 436 437 # Output looks like: 438 # Type: Argon2id 439 # Iterations: 3 440 # Memory: 65536 KB 441 # Parallelism: 4 442 # Hash: <hex> 443 # Encoded: $argon2id$v=19$m=65536,t=3,p=4$... 444 # Verification ok 445 ``` 446 447 ### With custom parameters 448 449 ```bash 450 # -t = time cost (iterations), -m = memory (2^m KB), -p = threads, -l = output length 451 echo -n "Password123" | argon2 "$(openssl rand -hex 8)" -id -t 3 -m 17 -p 4 -l 32 452 453 # Paranoid settings (512 MB RAM, 10 iterations) 454 echo -n "Password123" | argon2 "mysalt12345678!!" -id -t 10 -m 19 -p 8 -l 64 455 ``` 456 457 ### Parameter guide (OWASP 2024) 458 459 | Profile | `-t` | `-m` | `-p` | RAM | 460 |---|---|---|---|---| 461 | Minimum | 1 | 19 | 1 | 512 MB | 462 | Balanced | 3 | 17 | 4 | 128 MB | 463 | Low-memory | 5 | 14 | 2 | 16 MB | 464 465 ### Get only the encoded hash (PHC string format) 466 467 ```bash 468 echo -n "Password123" | argon2 "mysalt12345678!!" -id -e 469 # Output: $argon2id$v=19$m=65536,t=3,p=4$<base64salt>$<base64hash> 470 ``` 471 472 ### Verify a password against a stored hash 473 474 ```bash 475 echo -n "Password123" | argon2 "mysalt12345678!!" -id -v \ 476 '$argon2id$v=19$m=65536,t=3,p=4$bXlzYWx0MTIzNDU2NzgheA$<hash>' 477 # Output: Verification ok (exit 0) or Verification failed (exit 1) 478 ``` 479 480 --- 481 482 ## 9. bcrypt via htpasswd 483 484 The standalone `bcrypt` CLI is rarely packaged by distros. The easiest way to use bcrypt from the command line is `htpasswd` (from the `apache2-utils` package), which natively outputs `$2y$` bcrypt hashes. 485 486 ### Install 487 488 ```bash 489 sudo apt install apache2-utils # Debian/Ubuntu 490 sudo dnf install httpd-tools # Fedora/RHEL 491 brew install httpd # macOS 492 ``` 493 494 ### Hash a password (bcrypt, cost 12) 495 496 ```bash 497 htpasswd -bnBC 12 "" "Password123" | tr -d ':\n' 498 # -b = batch mode (password on CLI) 499 # -n = print to stdout (don't write a file) 500 # -B = force bcrypt 501 # -C = cost factor (4–31, default 5, use >=12 in production) 502 # The "" is a dummy username; tr strips it and the trailing newline 503 ``` 504 505 ### Output looks like 506 507 ```text 508 $2y$12$GiY13p14H9JQ3jHn3/XCDO6XuIBMH6PetA8SFO3T0d2EqLRUDtL7. 509 ``` 510 511 The `$2y$` prefix identifies this as a bcrypt hash. `$12$` is the cost factor. 512 513 ### Verify (htpasswd can't verify standalone — use python3 one-liner) 514 515 ```bash 516 python3 -c " 517 import bcrypt, sys 518 h = b'\$2y\$12\$...' # paste your stored hash here 519 p = b'Password123' 520 print('MATCH' if bcrypt.checkpw(p, h) else 'NO MATCH') 521 " 522 ``` 523 524 ### Cost factor timing guide 525 526 ```bash 527 # Benchmark: how long does cost 12 take on your machine? 528 time htpasswd -bnBC 12 "" "benchmark" > /dev/null 529 # Aim for 250ms–1s per hash in production 530 ``` 531 532 | Cost | Approx time (modern CPU) | 533 |---|---| 534 | 10 | ~100 ms | 535 | 12 | ~400 ms | 536 | 14 | ~1.5 s | 537 | 16 | ~6 s | 538 539 > **Note —** bcrypt hard limit: bcrypt only hashes the first **72 bytes** of input. Passwords longer than 72 chars are silently truncated. Pre-hash with SHA-256 if you need to support longer passphrases. 540 541 --- 542 543 ## 10. Comparing & Verifying Hashes 544 545 ### Constant-time comparison (avoid timing attacks in scripts) 546 547 ```bash 548 # Never use == in bash for hash comparison — it's not constant-time. 549 # Use python3 for safe comparison: 550 python3 -c " 551 import hmac 552 a = 'aabbcc112233' 553 b = 'aabbcc112233' 554 print('MATCH' if hmac.compare_digest(a, b) else 'NO MATCH') 555 " 556 ``` 557 558 ### Verify a SHA-256 checksum manually 559 560 ```bash 561 EXPECTED="e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" 562 ACTUAL=$(echo -n "" | sha256sum | cut -d' ' -f1) 563 [ "$EXPECTED" = "$ACTUAL" ] && echo "OK" || echo "MISMATCH" 564 ``` 565 566 ### Check if a file has been tampered with 567 568 ```bash 569 # Store hash before sending/storing 570 sha256sum important.bin > important.bin.sha256 571 572 # Verify on the other end 573 sha256sum -c important.bin.sha256 574 ``` 575 576 --- 577 578 ## 11. Cracking — hashcat & john 579 580 ### hashcat — GPU-accelerated 581 582 ```bash 583 # Identify hash type: https://hashcat.net/wiki/doku.php?id=hashcat 584 hashcat --identify hash.txt 585 586 # Dictionary attack 587 hashcat -m 0 hash.txt wordlist.txt # MD5 588 hashcat -m 100 hash.txt wordlist.txt # SHA-1 589 hashcat -m 1400 hash.txt wordlist.txt # SHA-256 590 hashcat -m 1800 hash.txt wordlist.txt # sha512crypt ($6$) 591 hashcat -m 3200 hash.txt wordlist.txt # bcrypt ($2*) 592 hashcat -m 13400 hash.txt wordlist.txt # KeePass 593 hashcat -m 16300 hash.txt wordlist.txt # Ethereum Pre-Sale Wallet 594 595 # Rules (mangling) — -r applies transformation rules 596 hashcat -m 0 hash.txt wordlist.txt -r /usr/share/hashcat/rules/best64.rule 597 598 # Brute force (mask attack) — ?l=lowercase, ?u=upper, ?d=digit, ?s=special 599 hashcat -m 0 hash.txt -a 3 ?l?l?l?l?l?l?l?l # 8 lowercase chars 600 hashcat -m 0 hash.txt -a 3 ?u?l?l?l?d?d?d?d # Password1234 pattern 601 602 # Combination attack (combine two wordlists) 603 hashcat -m 0 hash.txt -a 1 wordlist1.txt wordlist2.txt 604 605 # Show cracked passwords 606 hashcat -m 0 hash.txt --show 607 608 # Resume a session 609 hashcat --session mysession --restore 610 ``` 611 612 ### john the ripper — CPU-based 613 614 ```bash 615 # Auto-detect format and crack 616 john hash.txt 617 618 # With a wordlist 619 john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt 620 621 # Specify format explicitly 622 john --format=bcrypt hash.txt --wordlist=rockyou.txt 623 john --format=sha512crypt hash.txt --wordlist=rockyou.txt 624 john --format=argon2 hash.txt --wordlist=rockyou.txt # needs jumbo build 625 626 # Rules 627 john --wordlist=rockyou.txt --rules=best64 hash.txt 628 629 # Incremental (brute force) 630 john --incremental hash.txt 631 632 # Show cracked passwords 633 john --show hash.txt 634 635 # List supported formats 636 john --list=formats | grep -i bcrypt 637 john --list=formats | grep -i argon 638 ``` 639 640 ### Hash format quick reference for hashcat `-m` 641 642 | Algorithm | `-m` value | 643 |---|---| 644 | MD5 | 0 | 645 | SHA-1 | 100 | 646 | SHA-256 | 1400 | 647 | SHA-512 | 1700 | 648 | BLAKE2b-512 | 600 | 649 | bcrypt `$2*$` | 3200 | 650 | sha256crypt `$5$` | 7400 | 651 | sha512crypt `$6$` | 1800 | 652 | PBKDF2-HMAC-SHA256 | 10900 | 653 | scrypt | 8900 | 654 | Argon2id | 35700 | 655 | Argon2i | 35600 | 656 | Argon2d | 35500 | 657 658 --- 659 660 ## 12. Quick Reference Table 661 662 | Algorithm | CLI Tool | Install | Salt | Work Factor | Password Safe? | 663 |---|---|---|---|---|---| 664 | MD5 | `md5sum` | coreutils | No | No | Never | 665 | SHA-256 | `sha256sum` | coreutils | No | No | Never | 666 | SHA-512 | `sha512sum` | coreutils | No | No | Never | 667 | BLAKE2b | `b2sum` | coreutils | No | No | Never | 668 | PBKDF2 | `openssl kdf` | openssl | Yes | iterations | OK if tuned | 669 | scrypt | `openssl kdf` | openssl | Yes | N, r, p | Good | 670 | bcrypt | `htpasswd -B` | apache2-utils | Yes (built-in) | cost 4–31 | Good | 671 | Argon2id | `argon2` | argon2 pkg | Yes | t, m, p | Best | 672 673 --- 674 675 ## 13. Which Algorithm Should I Use? 676 677 ```text 678 Storing passwords? 679 └─ Use Argon2id (first choice) or bcrypt (widely supported) 680 └─ PBKDF2 only if FIPS compliance is required 681 682 File integrity / checksums? 683 └─ SHA-256 or SHA-512 (standard) 684 └─ BLAKE2b if you want faster with same security level 685 686 HMAC / message authentication? 687 └─ HMAC-SHA256 or HMAC-SHA512 (openssl dgst -hmac) 688 689 Key derivation from a password (e.g. for encryption)? 690 └─ scrypt or Argon2id 691 └─ PBKDF2 (FIPS environments) 692 693 Never use MD5 or SHA-1 for security-sensitive work. 694 ``` 695 696 > **OPSEC reminder —** Avoid passing passwords as CLI arguments (`-pass pass:...`) on shared/production systems — they appear in `ps aux` and shell history. Use `stdin`, env vars, or a secure prompt where possible.