Again, an example of this is the 3DES encrypt/decrypt/encrypt process vs. a more naive encrypt/encrypt/encrypt process. One is substantially stronger than the other. One is a secure way to use DES, and one is not.
Again, an example of this is the 3DES encrypt/decrypt/encrypt process vs. a more naive encrypt/encrypt/encrypt process. One is substantially stronger than the other. One is a secure way to use DES, and one is not.
Schneier all but disavowed _Applied Cryptography_ in _Practical Cryptography_.
Schneier's reputation as a cryptanalyst is, as even he might concede at this point, somewhat outstripping his actual career.
Bcrypt is part of the academic literature; the people who wrote it are both renowned.
You can make your same critique about any other crypto construction; maybe the OCB block cipher mode is unsafe! After all, Bruce Schneier didn't write it!
bcrypt is not an encryption algorithm. It doesn't "protect" your users' data, so there's no reason to trust or not trust it with their data.
If you don't believe me, consider this hash function
H(A) = (A>>1)&0xFFFFFFFF
There. Hash function. It sends any input to a 32 bit value. Would you use it for your password though? No. I certainly would not.
Granted, that is an incredibly weak example, but it's one that's easy to see why it's weak, and thus why a hash function does protect a user's data.