Totally agree Coda gets the basics right and I love that article. In fact, our CTO wrote a response blog article to that in February: http://www.stormpath.com/blog/strong-password-hashing-apache...
However, to quote from that post: "The author is correct assuming the attacker has direct access to your password store. This is a big assumption - most organizations go through great lengths to ensure access to say, databases, is levels of security 'deep' beyond just a web login form. Anyway, assuming that this might ever happen to you, how can you address the issue?"