Consult a doctor Design and implementation of a password hashing setup is serious business Larger organizations (with millions of users or with particularly high-value accounts - e.g., online banking) may benefit from custom setups, but independent review by a qualified consultant is a must Smaller organizations are better off using pre-existing solutions Currently this means straightforward use of bcrypt A short-term recommendation only, unfortunately Independent review is highly desirable, but is not crucial