Of course, having a broad understanding of cryptographic algorithms doesn't guarantee being a good pundit on security issues.
(Schneier has written some perfectly decent books in his security-pundit role, too, but they aren't definitive in the way that "Practical Cryptography" arguably was.)
"Applied" is "definitive" among laypeople and generalist programmers. "Practical" is an excellent book, but I dispute that it is in any way "definitive". More people have the evil red book on their desk than the good black book.
There's a reason why I put "arguably" in front of "definitive" :-). But the point is that what got Schneier famous was writing a big fat book, with lots of technical content, that a lot of people read and were impressed by. That may be less solid than writing a big book that deserves to impress everyone, but it's not at all the same thing as pure blogging bloviation.
(AC doesn't seem so very bad to me, aside from being out of date and being too much of an unassimilated algorithm-dump, but then I'm a generalist rather than a security professional.)
Here's the passage I was thinking of in "Practical":
Among cryptographers, Bruce's first book, Applied Cryptigraphy, is both famous and notorious. It is famous for bringing cryptography to the attention of thousands of people. It is infamous for the systems that these people then designed and implemented on their own.
The problems with AC include:
* No attention given to any of the practical vulnerabilities in cryptosystems, so that you could deploy code directly from the book and still have it be vulnerable to ECB cut-and-paste or parameter tampering.
* A candy shop of random ciphers without any context as to why one would be chosen over the other, with varying degrees of detail provided for each.
* Descriptions of protocols that are largely obsolete or discredited, without warnings or disclaimers or, really, any actual didactic purpose.
"Applied" seemed great to me too, but then I became a practioner (though by no means an expert). Even "Practical" lacks detail on a lot of major crypto issues --- side-channel attacks, parameter tampering, the safe use of public key primitives and signature validation --- that actually occur in real systems.
Since you seem to have a lot of experience in this area, what would you recommend as really good reading?
I would say one of the best things about "Practical" is that it will leave you feeling even less prepared to implement a cryptosystem on your own, even though you'll know much more about how to do it.
We're talking about the computer security industry, here. They have different standards when it comes to ego, and Schneier isn't actually that bad.