You're referring to simple dictionary attacks on a large database of passwords? Even bcrypt won't help much with a password from the top 10k list. I wouldn't say that stopping rainbow tables is "virtually no protection". Please explain what you're referring to.
[edit]
Does anyone know if the bitcoin ASICS have been repurposed as SHA256 crackers? md5 and sha-1 are more common in password storage, but if you use what the parent suggests, then it could be worse since there is so much specialized SHA256 hardware out there.
You misunderstand me. Please have a look at my reply to pbsd, I think it addresses your comments there too:
https://news.ycombinator.com/item?id=8087975
I did say there: "I stand corrected about KDFs not being OK for password storage".
At this point, given the content on this thread, it seems that it's been explained clearly enough why salted SHAx is inadequate to that task. Do you still not understand why that is?
Until Windows finally got plugged into the Internet and the weak LANMAN hash became relevant to hackers, nobody used "rainbow tables" to break passwords (classic Unix crypt passwords aren't particularly vulnerable to them, since they're salted). But --- and this is crucial --- everyone cracked Unix password files. All of the original password cracking tools, from Crack through JtR, were designed to quickly crack salted hashes.
Don't worry, I understand very well (this is not rocket science :P).
My problem, I think, was an inappropriate attitude toward the realities of stored password hashes on servers, in addition to having read that "scrypt is bad for password storage" (and having misunderstood the "badness" of it). I had read too many articles that treated HASH + SALT as "OK" for servers that stored user passwords, and I hadn't kept fresh in my mind the speed with which these passwords can be cracked today.
For example, take the article I linked to in my reply to pbsd: https://crackstation.net/hashing-security.htm (recently written).
This article, and many many others like it, are written by seemingly reputable people, and yet their attitude is that HASH + SALT is OK for servers. Even though it discusses bcrypt, etc., it frames it as though it's an "optional" hardening technique, and places HASH + SALT under the category of "proper hashing":
https://crackstation.net/hashing-security.htm#properhashing
I haven't seen them called out on it. I agree with you and the others in this thread, that it isn't good advice. If 10-char passwords can be protected better with KDFs, then they should be.
I don't know what the "security community" is, but if it has any relation to "the community of people who can speak with any authority on cryptography", let me ruefully assure you that it is much, much smaller than you think it is.
Thanks for making that very clear. :)
Re "security community", sorry, I'd edited that part out before I saw your reply, and replaced it with a call for these posts to be called out for giving bad advice.