Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Security operations track · 3 min

Tamper-evident logs: a hash chain

Edit one entry and watch every later hash break.

The idea

  1. 1A hash is a fingerprint

    Hashing turns any text into a short fixed fingerprint. Change one character and the fingerprint changes completely.

  2. 2Chain the fingerprints

    Each entry stores the fingerprint of the entry before it. Altering an old entry changes every one that follows.

  3. 3Tampering becomes visible

    Anyone holding the latest fingerprint can recompute the chain and see where it breaks.

  4. 4A general idea

    This is a concept used in many systems. Try breaking the chain below.

Try it

Edit an entry

Change any event text. The hashes are real SHA-256, shortened to 10 characters.

This exercise needs JavaScript. Here is the answer key.

  1. asha signed in
  2. admin changed a role
  3. log export requested
  4. asha signed out

Check yourself

1 of 3 What changes when one old entry is edited?

2 of 3 Does a hash chain stop someone editing?

3 of 3 What does a verifier need?

Answer key
  1. What changes when one old entry is edited? Every later hash. Each hash includes the previous one.
  2. Does a hash chain stop someone editing? No, it makes edits detectable. Detection, not prevention.
  3. What does a verifier need? The entries and a trusted latest hash. Then it can recompute and compare.