A more general point is that you should never roll your own crypto and if you must then it should be submitted for peer review by cryptographers before using it in a security critical application.
I know this is a pretty standard way to carry a technical conversation in the crypto community, but this is a pure and unadulterated argument from authority. I don't think other fields of computer science get away with this bullshit (you can't invent anything new unless you get a blessing from "the community").