ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 41

  1. Blog
  2. /Observability & SRE

hashlib md5 vs blake2b: Checksum Lab

Hands-on hashlib md5 vs blake2b vs sha1/sha256 lab: real MB/s checksum throughput for content-integrity hashing, measured on Linux localhost for SREs.

Aditya Challa·30 September 2026·4 min read

Lab
On this page
  1. Intro — what this post promises
  2. Arms
  3. Lab topology
  4. Lead table — oneshot 16 MiB (p50)
  5. Chunked 16 MiB & many 1 KiB
  6. Reading it
  7. OpenSSL can invert folklore
  8. Pitfalls
  9. When to pick what
  10. Reproduce
  11. Closing

Intro — what this post promises

Content checksums: how do hashlib.md5, sha1, blake2b, and sha256 compare on MB/s for integrity hashing? This is a throughput lab, not crypto advice — MD5/SHA-1 are broken for collision resistance and appear here only as legacy checksum baselines.

Related links:

  • SHA-256 vs BLAKE2 vs xxHash localhost lab
  • glob vs rglob vs walk localhost lab
  • shutil copyfile vs manual localhost lab
  • bytes vs bytearray localhost lab
  • json dumps compact vs indent localhost lab
  • str translate vs replace localhost lab
  • setdefault vs defaultdict localhost lab
  • perf_counter vs time localhost lab

Lab honesty (1 Oct 2026 IST): Python 3.13.5; OpenSSL 3.5.7 9 Jun 2026. Stdlib hashlib only (no xxhash — that was lab 35). Affiliates: 0. OpenSSL may accelerate SHA-2 heavily on this CPU.

Verdict up front (16 MiB oneshot): sha256 ~1468 MB/s, sha1 ~1320, md5 ~664, blake2b ~500. md5÷sha256 ~0.45×; blake2b÷sha256 ~0.34×. On this OpenSSL build, SHA-256 outran MD5 — measure your box before assuming “MD5 is the fast checksum.”


Arms

ArmNotes
md5 / sha1legacy checksums — speed only
blake2b / blake2b(digest_size=32)hashlib BLAKE2
sha256OpenSSL-backed
oneshot vs 1 MiB chunked updatesstreaming pattern
many 1 KiB digestsper-object checksum churn

Lab topology

buffers: 64KiB / 1MiB / 16MiB os.urandom
chunked: 16×1MiB updates; many-small: 20000×1KiB
metric: p50 MB/s

Script: lab-evidence/77-hashlib-md5-vs-blake2b/results/run_lab.py.


Lead table — oneshot 16 MiB (p50)

AlgoMB/svs sha256
sha25614681.00×
sha113200.90×
md56640.45×
blake2b (32)6670.45×
blake2b (64)5000.34×

Chunked 16 MiB & many 1 KiB

Algochunked 16 MiB MB/smany-1 KiB MB/s
sha2561477925
sha11647968
md5671514
blake2b658589

Chunking ≈ oneshot for md5/sha256 here (~1.01× / ~1.01×). Many small digests shift rankings (constructor overhead) — blake2b closed on sha256 (~0.64×).


Reading it

  • Do not assume MD5 is the throughput king — with OpenSSL SHA-NI-style acceleration, sha256 won the large-buffer race on this host.
  • BLAKE2b default (64-byte digest) was slower than sha256 for big oneshots; digest_size=32 helped some sizes.
  • Lab 35 already covered xxHash vs blake2/sha256 for non-crypto fingerprinting — use that when you need non-cryptographic ultra-speed; this lab stays on hashlib checksums.
  • Integrity ≠ security — for passwords/signatures use modern KDFs / SHA-2+/SHA-3 as policy requires; this post only ranks digest speed.

OpenSSL can invert folklore

Many engineers still assume “MD5 is the cheap checksum.” On this host’s OpenSSL build, SHA-256 oneshot throughput beat MD5 by roughly 2× on a 16 MiB buffer. Hardware SHA extensions and library optimizations matter more than textbook relative costs from the 1990s. Always bench the digests you ship in an integrity pipeline.


Pitfalls

  1. Choosing MD5 “because it’s fast” without measuring — may be false on modern OpenSSL.
  2. Using MD5/SHA-1 for security — collision attacks; don’t.
  3. Ignoring many-small vs bulk — API overhead changes winners.
  4. Comparing to xxhash without saying so — different tool class (see lab 35).

When to pick what

NeedPrefer
Default modern checksumsha256 (often HW-fast)
Interop with legacy digestsmd5/sha1 (explicitly labeled legacy)
hashlib BLAKE2blake2b (tune digest_size)
Non-crypto ultra-speedxxhash / lab 35

Reproduce

python3 lab-evidence/77-hashlib-md5-vs-blake2b/results/run_lab.py

Evidence: /workspace/lab-evidence/77-hashlib-md5-vs-blake2b/results/.


Closing

Measure checksums on your OpenSSL; don’t mythologize MD5 speed. On this box 16 MiB sha256 hit ~1468 MB/s, beating md5 (~664, ~0.45×) and default blake2b (~500, ~0.34×). Use these numbers for integrity-pipeline capacity planning — not as a cryptography shortlist.

hashlibmd5blake2bsha256sha1checksumpythonlocalhost lab

Lab evidence

What I found running this

Lab 1 Oct 2026 IST. Python 3.13.5; OpenSSL 3.5.7 9 Jun 2026. 16MiB oneshot: sha256 1468 MB/s; sha1 1320; md5 664; blake2b 500 (md5÷sha2560.45x; blake2b÷sha2560.34x). Integrity/checksum speed only — not security advice. Differs from lab 35 (no xxhash; +md5/many-small). Affiliates: 0. Evidence: lab-evidence/77-hashlib-md5-vs-blake2b/.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 18

    fnmatch vs re Name Filter: Localhost Lab

    Hands-on fnmatch.filter vs re.compile name-list filtering measured on Linux localhost.

    Observability & SRE · 30 Sept 2026

  • Plate 84

    tarfile vs zipfile Create+Extract: Localhost Lab

    Hands-on tarfile vs zipfile create+extract lab: real MB/s on a mixed small-file fixture (uncompressed tar vs zip), measured on Linux localhost for SREs.

    Observability & SRE · 30 Sept 2026

  • Plate 85

    scandir vs listdir vs iterdir: Localhost Lab

    Hands-on os.scandir vs listdir vs Path.iterdir lab: real entries/s for names and is_file on a synthetic tree, measured on Linux localhost (lab) for SREs.

    Observability & SRE · 30 Sept 2026

On this page

  1. Intro — what this post promises
  2. Arms
  3. Lab topology
  4. Lead table — oneshot 16 MiB (p50)
  5. Chunked 16 MiB & many 1 KiB
  6. Reading it
  7. OpenSSL can invert folklore
  8. Pitfalls
  9. When to pick what
  10. Reproduce
  11. Closing
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove