It's important to remember one key takeaway from this. It still applies to offline hashes.
That means, if your db is compromised, it's pretty much game over for your users (who will invariably reuse them elsewhere) if you used simple hashes - another key takeaway. Bcrypt (or better yet, scrypt) is still the better option for this very reason.
Edit: To clarify, it doesn't matter that you limit logins, lockout users after failed login attempts etc... (although, those are good measures to start) The password hashing scheme must withstand bruteforce cracking of this nature to a feasible degree regardless of what limiting protocols you have in place. Just in case...
That means, if your db is compromised, it's pretty much game over for your users (who will invariably reuse them elsewhere) if you used simple hashes - another key takeaway. Bcrypt (or better yet, scrypt) is still the better option for this very reason.
Edit: To clarify, it doesn't matter that you limit logins, lockout users after failed login attempts etc... (although, those are good measures to start) The password hashing scheme must withstand bruteforce cracking of this nature to a feasible degree regardless of what limiting protocols you have in place. Just in case...