Agreed with the way it could be done better though they didn't actually have the private key on the system. They really badly implemented their crypto so they might as well have though.
I'm referring purely to the dongle attack. When you use an HMAC in that way, your secret is your "private" key. It also just happens to be the "public" key as well. That's why it's a terrible design.