> most software in the world uses a basic hash like MD5 or SHA-256 rather than a key derivation function
For passwords? Where do you get that information?
For passwords? Where do you get that information?
Even if only 10% of the services you use use MD5/SHA-256 (although I certainly would expect it to be >50% if we could do a large-scale study), why accept your password being easily compromised 10% of the time?
Those services using md5 aren't doing important things, I hope, so the password for that service hardly matters.
If it does matter, then user long passwords/phrases and rotate every time (or find a better supplier).