PBKDF2 password hash and verify

Derive a salted PBKDF2-SHA-256 or SHA-512 password hash, or verify a password against an encoded value.

OWASP recommends 600,000 iterations for SHA-256 and 210,000 for SHA-512: the more there are, the more each attacker guess costs.