This has nothing to do with smugness. If you market your product as a secure alternative, it better be secure.
The "smugness" is pointing out problems in their implementation, despite them going on about having "ACM champions" that took two years to design it, so it obviously must be perfect.
If someone pitched a database that simply mmap'd a file and then called it "fully transactional and safe", they'd get a lot of strong criticism.
This kind of attitude (trust us, we have enough credentials to show) seems to be a universal problem with people in academics. Come on, don't do this. We all get the sense that you have to bluff to get your paper published, but this is not going to work for a product to be accepted.