diff --git a/django/contrib/auth/hashers.py b/django/contrib/auth/hashers.py index 59676f6562..9aac881643 100644 --- a/django/contrib/auth/hashers.py +++ b/django/contrib/auth/hashers.py @@ -221,7 +221,7 @@ class PBKDF2PasswordHasher(BasePasswordHasher): """ Secure password hashing using the PBKDF2 algorithm (recommended) - Configured to use PBKDF2 + HMAC + SHA256 with 20000 iterations. + Configured to use PBKDF2 + HMAC + SHA256 with 24000 iterations. The result is a 64 byte binary string. Iterations may be changed safely but you must rename the algorithm if you change SHA256. """