Here's the passage I was thinking of in "Practical":
Among cryptographers, Bruce's first book, Applied Cryptigraphy, is both famous and notorious. It is famous for bringing cryptography to the attention of thousands of people. It is infamous for the systems that these people then designed and implemented on their own.
The problems with AC include:
* No attention given to any of the practical vulnerabilities in cryptosystems, so that you could deploy code directly from the book and still have it be vulnerable to ECB cut-and-paste or parameter tampering.
* A candy shop of random ciphers without any context as to why one would be chosen over the other, with varying degrees of detail provided for each.
* Descriptions of protocols that are largely obsolete or discredited, without warnings or disclaimers or, really, any actual didactic purpose.
"Applied" seemed great to me too, but then I became a practioner (though by no means an expert). Even "Practical" lacks detail on a lot of major crypto issues --- side-channel attacks, parameter tampering, the safe use of public key primitives and signature validation --- that actually occur in real systems.