You can change a password, and you can calculate how hard it is to for an attacker to obtain a randomly generated password.
It is much harder to formalise how hard it is for an attacker to find out what algorithm you use, so it is risky relying too much on him not being able to do so.