His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…
It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit.
Not saying there aren't risks out there, just that the industry markets itself through bombast and sometimes exaggerates them.
Back to the infosec realm, the simple truth is that the only absolutely secure system is one that is off and the only absolute privacy is in your own head (maybe). Everything else is a matter of degrees of risk, and the curve is hockey stick shaped. It's relatively easy to mitigate the big risks, but that leaves a long tail of small risks and small vulnerabilities that require an exponentially increasing amount of effort and inconvenience to deal with.