You cannot assume that an attacker will have an "honor code" or that you can keep information secret from an attacker. Because of the latter one, there exists Kerckhoff's principle
> https://en.wikipedia.org/w/index.php?title=Kerckhoffs%27s_pr...
which on a high level states that security by obscurity will in the long run become broken (and as a corollary DRM does not work).
I suppose it's a good reminder that in the real world, the easiest way in is often through a gullible or untrustworthy employee.
The key seemed to be the descrambler.
Why on earth did they scramble the executable in a deterministic way?
Because they wanted official developers to be able to create MIL-CDs that would load.
They just didn't want anyone else being able to do that.
https://en.wikipedia.org/wiki/PlayStation_3_homebrew#Private...
(I would _suspect_ that internally, they deliberately made this choice, so that the same inputs would produce the same output, because someone important thought that was valuable and either didn't know or thought it wasn't risky enough to possibly leak key information by doing this. But I have no special knowledge, just a suspicion that people who pick elliptic curve crypto would be aware of the leaks involved in reusing IVs.)