I don't buy the line that open source is "better because everyone is checking for bugs" line, but the bottom line point from my perspective is that the openness of a specification does not, in fact, make it easier to intrude upon an implementation of that spec.
A completely valid argument -- and possibly a persuasive one as well, if the boss is smart - involves the comparison of an open and strong encryption algorithm vs and weak but closed one.
This is where wars are won. If security through obscurity can't keep wartime governments in power, it probably doesn't do much.