SHA-1, SHA-256, Security

SHA-1 is faster, but considered unsecure. See shattered PDFs: one and two, producing the same digest:

  sha1sum shattered-1.pdf
  38762cf7f55934b34d179ae6a4c80cadccbb7f0a ...

  sha1sum shattered-2.pdf
  38762cf7f55934b34d179ae6a4c80cadccbb7f0a ...

  cmp shattered-1.pdf shattered-2.pdf 
  shattered-1.pdf shattered-2.pdf differ: \
    byte 193, line 8    
    
Checksum Commands
CommandLhexLbNote
crc32832insecure
md5sum32128insecure
shasum40160SHA1 (-a 1) by default
sha1sum40160insecure
sha224sum56224crypto. discouraged
sha256sum64256secure
sha384sum96384secure
sha512sum128512secure

Checksum Binaries.

All commands are used similarly:

  md5sum path/1.txt
  2434e28d340b668ec1918bf08af69f47 path/1.txt
  

Verification from file is done with -c (exc. crc32)

  md5sum -c sums.txt
  

Diffing Recursive Checksums.

Usage example for checksums, after a copy operation from a mounted device that was interrupted, some files may be corrupted. This operation outputs cryptographic checksums mapped to file paths, relative top.

  # Checksums all cwd files recursively.
  # Output lines are '[hexsum] [relpath]'
  # Ordered by hexsum, from (0.*) to (f.*)
  alias rsum="find . -type f \
    -exec md5sum '{}' + | sort"
  

It can be used to save files recursively listing files and checksums in source and destination top dirs.

  (cd /media/path/usb_key && rsum) >sums1.txt
  (cd /home/path/copydest && rsum) >sums2.txt
  

Files can be individually inspected, parsed, or using diff, can be compared to ensure each file are byte-identical copies. Diffing will output only files that have diverged, or are missing.

  # no output := all copies identical
  diff sums1.txt sums2.txt

  # output if 1.txt edited and 2.txt missing
  diff sums1.txt sums2.txt

  54a55
  > 5f6472b03a20e5ad7636178a435c2519  ./1.txt
  85d85
  < 86f855474eab862e72c7e14328abbea4  ./2.txt
  90d89
  < 8afd238896d55910928ca128ac96f387  ./1.txt