to slow down attackers who want to brute force your password hash. At least that was the idea. I guess it also includes the salt stuff built in so that it's harder for implementers to screw up.
Is a 9-order-of-magnitude slow down worth the trouble? I dunno. Maybe.