!!!!!!
!!!!!!
SHA2 is very fast.
From the "Cryptographic Right Answers" [https://latacora.micro.blog/2018/04/03/cryptographic-right-a...]:
> Latacora, 2018: In order of preference, use scrypt, argon2, bcrypt, and then if nothing else is available PBKDF2.
> Avoid: SHA-3, naked SHA-2, SHA-1, MD5.
SHA2 is a decent cryptographic hashing algorithm, that is true. But a cryptographic hashing algorithm isn't what you want when storing passwords, at least, not on its own.
Some of the problems with just using a hash algorithm: same passwords have the same hash; hash algos are typically fast, so brute forcing can make many attempts quickly, and they can be pre-computed into rainbow tables. There are ways to fix this (salts, work factors), but generally you shouldn't "do it yourself."; functions like those named in the quote from Cryptographic Right Answers put all that together in a nice package. scrypt, I believe, even uses SHA-2 in its construction, but also solves the aforementioned problems.
The "Purpose and operation" part of the Wikipedia article for PBKDF2 (also mentioned above) goes into some of this, as well (even if it is only recommended as a last resort, I think this paragraph is educational w.r.t. the problems around passwords): https://en.wikipedia.org/wiki/PBKDF2#Purpose_and_operation
His lib is can be dropped in to any project (that doesn't have something similar built in already) https://github.com/iamcal/lib_bcrypt
Anyone writing code has no excuse for not using this, it's not rocket surgery.
;)