KDFs are not for storing password hashes, they are for key derivation. This is a subtle point, the main thing is to use KDFs as KDFs (to derive keys that are then used to encrypt data). Details in the first link here (the second is about common mistakes when using scrypt):
- http://blog.ircmaxell.com/2014/03/why-i-dont-recommend-scryp... (bad title, he's referring to pass storage, not KDF usage)
- http://vnhacker.blogspot.com/2014/04/fairy-tales-in-password...
Another consideration is plausible deniability (PD) for situations where you're compelled to disclose your password(s). Our company writes Mac encryption software that specializes in this (and it uses scrypt). Here's a list of tools that offer PD (ours is called Espionage):
https://en.wikipedia.org/wiki/Deniable_encryption#Software
I compared Espionage's PD to TrueCrypt's on reddit:
http://www.reddit.com/r/security/comments/2b5icu/major_advan...