Architectural Breakdown: Django 6.1's PBKDF2 default change rewrites existing password hashes on nex
# Django 6.1's PBKDF2 Upgrade: How Automatic Hash Rewrites Became a Production Denial-of-Service Django 6.1 changed PBKDF2's default iterations from 1,200,000 to 1,500,000. The framework treats every existing hash as outdated and re-hashes it on the next login. That sounds like a feature until you have 30,000 active users and a single-column database write spike. ## The Upgrade Mechanism,…
Django 6.1 implemented a PBKDF2 default iteration change, raising the default to 1,500,000. Every existing hash is treated as outdated and re-hashed during the next login. This automatic re-hashing is problematic in production environments with many active users, as it introduces a denial-of-service risk.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.