I would like to disagree on that:
"It's not really about MD5, SHA1 or BCrypt, (...) It wouldn't matter if the passwords were all in plaintext if they never got out."
It is also about the hashes, because a good security infrastructure should anticipate the possibility of a leak and still protect the users.
For that, you need to use the right encryption so that users don't have to change their passwords in the next days, but have 5+ years for that.
And yes, I see that you are promoting dedicated authentication services (which would do it right), it just looks strange to me there.