Plate 41
hashlib md5 vs blake2b: Checksum Lab
Hands-on hashlib md5 vs blake2b vs sha1/sha256 lab: real MB/s checksum throughput for content-integrity hashing, measured on Linux localhost for SREs.
Aditya Challa4 min read
Intro — what this post promises
Content checksums: how do hashlib.md5, sha1, blake2b, and sha256 compare on MB/s for integrity hashing? This is a throughput lab, not crypto advice — MD5/SHA-1 are broken for collision resistance and appear here only as legacy checksum baselines.
Related links:
- SHA-256 vs BLAKE2 vs xxHash localhost lab
- glob vs rglob vs walk localhost lab
- shutil copyfile vs manual localhost lab
- bytes vs bytearray localhost lab
- json dumps compact vs indent localhost lab
- str translate vs replace localhost lab
- setdefault vs defaultdict localhost lab
- perf_counter vs time localhost lab
Lab honesty (1 Oct 2026 IST): Python 3.13.5; OpenSSL 3.5.7 9 Jun 2026. Stdlib hashlib only (no xxhash — that was lab 35). Affiliates: 0. OpenSSL may accelerate SHA-2 heavily on this CPU.
Verdict up front (16 MiB oneshot): sha256 ~1468 MB/s, sha1 ~1320, md5 ~664, blake2b ~500. md5÷sha256 ~0.45×; blake2b÷sha256 ~0.34×. On this OpenSSL build, SHA-256 outran MD5 — measure your box before assuming “MD5 is the fast checksum.”
Arms
| Arm | Notes |
|---|---|
| md5 / sha1 | legacy checksums — speed only |
| blake2b / blake2b(digest_size=32) | hashlib BLAKE2 |
| sha256 | OpenSSL-backed |
| oneshot vs 1 MiB chunked updates | streaming pattern |
| many 1 KiB digests | per-object checksum churn |
Lab topology
Script: lab-evidence/77-hashlib-md5-vs-blake2b/results/run_lab.py.
Lead table — oneshot 16 MiB (p50)
| Algo | MB/s | vs sha256 |
|---|---|---|
| sha256 | 1468 | 1.00× |
| sha1 | 1320 | 0.90× |
| md5 | 664 | 0.45× |
| blake2b (32) | 667 | 0.45× |
| blake2b (64) | 500 | 0.34× |
Chunked 16 MiB & many 1 KiB
| Algo | chunked 16 MiB MB/s | many-1 KiB MB/s |
|---|---|---|
| sha256 | 1477 | 925 |
| sha1 | 1647 | 968 |
| md5 | 671 | 514 |
| blake2b | 658 | 589 |
Chunking ≈ oneshot for md5/sha256 here (~1.01× / ~1.01×). Many small digests shift rankings (constructor overhead) — blake2b closed on sha256 (~0.64×).
Reading it
- Do not assume MD5 is the throughput king — with OpenSSL SHA-NI-style acceleration, sha256 won the large-buffer race on this host.
- BLAKE2b default (64-byte digest) was slower than sha256 for big oneshots;
digest_size=32helped some sizes. - Lab 35 already covered xxHash vs blake2/sha256 for non-crypto fingerprinting — use that when you need non-cryptographic ultra-speed; this lab stays on hashlib checksums.
- Integrity ≠ security — for passwords/signatures use modern KDFs / SHA-2+/SHA-3 as policy requires; this post only ranks digest speed.
OpenSSL can invert folklore
Many engineers still assume “MD5 is the cheap checksum.” On this host’s OpenSSL build, SHA-256 oneshot throughput beat MD5 by roughly 2× on a 16 MiB buffer. Hardware SHA extensions and library optimizations matter more than textbook relative costs from the 1990s. Always bench the digests you ship in an integrity pipeline.
Pitfalls
- Choosing MD5 “because it’s fast” without measuring — may be false on modern OpenSSL.
- Using MD5/SHA-1 for security — collision attacks; don’t.
- Ignoring many-small vs bulk — API overhead changes winners.
- Comparing to xxhash without saying so — different tool class (see lab 35).
When to pick what
| Need | Prefer |
|---|---|
| Default modern checksum | sha256 (often HW-fast) |
| Interop with legacy digests | md5/sha1 (explicitly labeled legacy) |
| hashlib BLAKE2 | blake2b (tune digest_size) |
| Non-crypto ultra-speed | xxhash / lab 35 |
Reproduce
Evidence: /workspace/lab-evidence/77-hashlib-md5-vs-blake2b/results/.
Closing
Measure checksums on your OpenSSL; don’t mythologize MD5 speed. On this box 16 MiB sha256 hit ~1468 MB/s, beating md5 (~664, ~0.45×) and default blake2b (~500, ~0.34×). Use these numbers for integrity-pipeline capacity planning — not as a cryptography shortlist.
Lab evidence
What I found running this
Lab 1 Oct 2026 IST. Python 3.13.5; OpenSSL 3.5.7 9 Jun 2026. 16MiB oneshot: sha256 1468 MB/s; sha1 1320; md5 664; blake2b 500 (md5÷sha2560.45x; blake2b÷sha2560.34x). Integrity/checksum speed only — not security advice. Differs from lab 35 (no xxhash; +md5/many-small). Affiliates: 0. Evidence: lab-evidence/77-hashlib-md5-vs-blake2b/.
Related links
Plate 18
fnmatch vs re Name Filter: Localhost Lab
Hands-on fnmatch.filter vs re.compile name-list filtering measured on Linux localhost.
Observability & SRE · 30 Sept 2026
Plate 84
tarfile vs zipfile Create+Extract: Localhost Lab
Hands-on tarfile vs zipfile create+extract lab: real MB/s on a mixed small-file fixture (uncompressed tar vs zip), measured on Linux localhost for SREs.
Observability & SRE · 30 Sept 2026
Plate 85
scandir vs listdir vs iterdir: Localhost Lab
Hands-on os.scandir vs listdir vs Path.iterdir lab: real entries/s for names and is_file on a synthetic tree, measured on Linux localhost (lab) for SREs.
Observability & SRE · 30 Sept 2026