Seems like the author is implying but not directly saying the hashed passwords were not salted. Am I reading that right, and does anyone know if they were salted?
However, if your password is "password" or another very common password, then someone can just try those with the embedded salt and still find out that was your password.
You'd still have to crack each password individually though, right? i.e. for row 1 I would need to try X passwords from my password dictionary, and for each of the attempts bcrypt the guess with the given salt and check to see if worked, and then repeat that for each row individually, rather than checking every row simultaneously.