NetTuts needs to mention which key derivation function they are using so the community can verify they didn't fuck up again. I would also recommend that they use this opporunity to teach their web developing users about proper password storage, but after reading their php hashing tutorial[1], I think it's best if their users look elsewhere. The tutorial eventually recommends bcrypt after listing multiple unsafe solut…
There's no real way to 'verify' this. They would have to provide the source code in its entirety and several card-carrying, certified cryptanalysts/cryptographers would have to vet it and then publicly approve of it. That will never happen. Users have to have some level of trust. Like everything else in life.
There is no real disadvantage to saying which one and a lot of trust to regain.