Password hashing
Storing passwords is a specialised job, and using the wrong tool for it is a common and serious mistake.
Ordinary hashes are designed to be fast, which is exactly wrong here, because fast means an attacker can try billions of guesses an hour. Purpose-built password hashing functions are deliberately slow and memory-hungry, so each guess costs real time and real hardware. This is one of the few places in security with a genuinely correct answer rather than a trade-off, and the difference between getting it right and getting it wrong shows up as the difference between a breach where passwords survive and one where they do not.
Checked against the primary source.
