To use crypto right requires knowledge of crypto systems. You're not going to know how to use crypto schemes correctly without knowing about common flaws and a range of side channel attacks. The crypto code itself is usually relatively easy to use (OpenSSL may have a clunky interface, but there are tons of examples out there). The problem here, and I'd argue actually in most cases, isn't that the libraries don't exist or are hard to use. The problem is that the people using said libraries don't know what they're doing.
There are great books out there that will tell you everything you need to know to understand and write safe crypto code. It's not some kind of closely guarded secret kept by an exclusive elite, it just requires reading. Pirate the books if you want to stop information hoarding among the rich, it's trivially easy to do with libgen.
You can roll your own crypto if you're capable of doing so, and have someone as competent as you check your work.
In this case, this tweet has listed the flaws that the custom crypto implementation has: https://mobile.twitter.com/gsuberland/status/153811763597137...
Some of these flaws aren't that bad (== vs === shouldn't matter too much in this case, though it's a sign of bad PHP code when the types are supposed to be well known). Others are either bad code practice (allowing a variable to be uninitialized) or well-known cryptographic mistakes that you'll learn to catch after reading a book or two (timing attack, shared keys). I won't pretend I would've spotted all of those at a glance, but I can admit that my crypto course has been too long ago for me to write or review such code.
I've got a basic grasp of electrical cirtuits but that doesn't mean I should be allowed to design highly secure electronic security circuits. I will miss important problems and dangerous flaws because I lack in-depth knowledge and experience. It's not because there's not an easy 1-2-3 guide on how to design safe circuits or because a cabal of academic elites are keeping this knowledge to themselves and pretending to do so just shifts the blame for my lack of effort to others.
Feel free to do your own crypto. Tons of companies do. You'd better put in the work to make sure you're doing it right, though! If you're working on some kind of new cryptographic structure and an academic writes up a theoretical attack in a paper somewhere, you're doing it right, assuming that you extend your scheme to solve the problems discovered. If you make textbook mistakes in important code, you're clearly doing it wrong.
If you're interested in learning cryptography so you can try to roll your own, I recommend starting with books like these:
- Cryptography Made Simple by Nigel Smart
- Applied Cryptography by Bruce Schneier
- Cryptography Engineering: design principles and practical applications by Neil Ferguson, Bruce Schneier, and Tadayoshi Kohno
These books require some prerequisite mathematical knowledge (like all crypto does) which you can probably pick up on Khan Academy. They go in depth into how common cryptography works, why these schemes are secure and how they can be broken (in theory and in practice). Some of them are getting old, though, so you may need to find some newer material if you're doing stuff like modern elliptic curve or post-quantum cryptography.