CouchDB uses SHA-1 hashes for passwords - you've got to be kidding me. What is the rationale for that over bcrypt?
I am not so sure of that.
And evidently the CouchDB guys agree with me, because they switched to using PBKDF2 for password storage -- essentially, iterate SHA several thousand times to make it slower.