You are probably not mistaken. Here are some things I've learned about SSIS package security:
If you set the Package ProtectionLevel property to EncryptSensitiveWithPassword and specify a password, the package will behave as you described - if and only if nothing is considered “sensitive” in the package. Essentially, this parameter is ignored (although the property parameter is saved) until something appears that SSIS considers "sensitive."
SSIS , . , . Windows, . SQL-, , EncryptSensitiveWithPassword ( - ). ( Windows, / ... , ...)
SSIS-, EncryptAllWithPassword ProtectionLevel. , -, - - .
, .
: { >