To take a concrete example of encryption using a key derived from a passphrase: SSH keys. OpenSSH uses MD5 as a key derivation function, so if someone steals a passphrased SSH key file you'd better hope that the passphrase is very strong.
I also had a quick look at the tarsnap source code, and I see you do exactly that for the passphrased keyfile.