That term is about hiding a system's design in order to secure something, rather than having secure design.
A secure system is impenetrable unless you have the key.
The world uses many security products that have false positives and false negatives (firewalls, intrusion detections, wafs, fraud detection, spam...). Those aren't generally considered security through obscurity.
They openly talk about the system and its drawbacks here if you're interested: https://www.anthropic.com/news/fable-safeguards-jailbreak-fr...
It's paired with rate limits, monitoring, account control, multiple classifiers, a deliberate safety margin, model design, and other things too.
(I think this was also why they faced the controversy over not having zdr in fable: they wanted to use logs to detect repeated attempts, etc. Possibly a bigger change with Opus/Sonnet is that it's zdr with the classifiers?)
The reason you see "dumb" refusals that "should clearly be allowed" is that they're using more traditional deterministic methods to deny prompts rather than just relying on the random LLM which you could bypass by luck.