Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...