Wow, you jumped right on that :) I deleted the comment immediately after posting it because I wasn't really sure I could support that statement. As someone who doesn't know a lot about security algorims, I'm susceptible to the idea posed in the article that the better-proven algorithm is a safer bet; but on second thought, it seemed a little paranoid, since I haven't seen any positive reason to doubt bcrypt's security. And given that PBKDF2 is an uglier thing to try to recommend, and "just use something" is the most important message, I think the current atmosphere around bcrypt is probably fine.