> Once a site gets big, does it just get too hard to scale or adapt to the third-party provider?
Or too expensive compared to doing it yourself.
There's also a difference between rolling your own crypto and rolling your own auth. Leave the actual hash to experts and use NaCL's argon2 implementation. The salt+hash are just more user metadata that aren't super sensitive given modern password hashing algorithms.