SHA-256. Did you? My point isn't constrained to this exact service, though. My point is that the XKCD-style passphrase is in general not secure. If you make a habit of using it, assuming that the service in question will take care of securing it super duper safely on your behalf, you will get bitten when a service doesn't do this.
If character class constraints are enforced then that password becomes incredibly strong though - e.g. require a capital, and special characters and a number.
Plenty of sentence passwords meet that but now the probability space has exploded.