When I discovered my company was encrypting passwords with SHA2, I tried explaining how this was wrong and got talked down by a coworker arguing that this was unimportant compared to the importance of making sure nobody gets to the database in the first place. She was basically saying that that's much more important and if that's done right then having strong encryption isn't that vital.
Unfortunately I didn't know enough to counterargue and had to say 'okay,' which bothers me to this day (several months later).
Can anyone explain why she was wrong, or conversely why she was right?