The opposite turns out to be true in practice. People have the choice of using a simple crypto library interface (like BouncyCastle PGP) or "really getting to understand" AES, and so end up fielding software with vulnerabilities PGP addressed in the '90s.
A pithier way to say the same thing is, "you're right, except for the words 'without understanding it'".
A pithier way to say the same thing is, "you're right, except for the words 'without understanding it'".