PBKDF2
Password-Based Key Derivation Function 2 (RFC 2898) — makes password-to-key conversion deliberately slow by HMAC-ing hundreds of thousands of iterations.
Design principle: raise the cost of brute-force by fixing the work per attempt. The user notices 100 ms at login; the attacker faces 100 ms × millions of attempts. Standard in WPA2, iOS keychain, 1Password, LUKS, .NET Rfc2898DeriveBytes.
Modern weakness: purely CPU-bound, so cheap to accelerate with GPU/ASIC. Argon2 and scrypt are memory-hard — attacker hardware scales worse. NIST still permits PBKDF2 (SP 800-132) but now recommends Argon2id for new systems.