How about this: Don't store passwords at all. There are a multitude of sophisticated third-party solutions to authentication. Facebook, Twitter, and Google all offer competent solutions. Don't like those? Use BrowserID. Integrating any of these is actually quite a bit easier than rolling your own solution. It reduces hack risk, provides a better experience for your customers (what was my password again?), and almost…
This naively assumes that your entire userbase uses those services and would like to attribute their Google (et al) account with your service. This may not always be the case. Someone has to store the passwords, it would be good if there was a way you could be assured your data at rest was safe.
Personally, I never feel particularly secure when typing passwords into text boxes on random PHP forms. On the other hand, I feel fairly confident that the folks at FB, Google, Twitter, and Mozilla know how to store a password and secure their infrastructure.