Hashing is not enough for passwords because rainbow tables and GPUs exist. You should always use an expensive key derivation function like pbkdf2, bcrypt, scrypt or preferably argon2. Sure, people call output of those functions a "hash", but it's not the same as just using SHA.