Earlier quoted context omitted.
Indeed. Encrypting your bcrypt'd hashes is... massively complex and doesn't provide any additional meaningful security relative to the complexity. A properly bcrypt'd password table is functionally useless in the hands of a non nation-state. Yeah, it's not something you'd prefer to have a BadGuy(TM) get, but other than embarrassment, it's not a big deal. Here's my bcrypt with salt. Please, waste your time trying to c…
I'm pretty sure your actual bcrypted password doesn't have that cost factor on it.
Shame on you, Thomas! I thought you were a professional!
[1] Based on a remarkably unscientific test I just ran on an Ubuntu 12.04 VM on my laptop. 87.8 seconds.