Very good point about hashed passwords stolen from server password stores. However, it may be dependant on the hash function used. If the function uses a SHA-256 to hash the password, the sun may burn out before it is cracked. For MD5 hashing, 40 minutes would crack most passwords.