His work on security in iOS is quite interesting, but he seems determined to spin everything for maximum publicity rather than, well, accuracy or truth, which is a shame. For example, on that blog post he writes about pcapd and developers: "Lets start with pcapd; I mentioned in my talk that pcapd has many legitimate uses such as these" Yet in the slides for his talk[1] under theories he writes" "Maybe for Developers…
You just described significant portions of the security industry, which runs on maximizing the fear and FUD factor. It's not just true of computer security. It's really true globally of the entire "security" sector, from infosec to police to the global "national security" defense/intelligence industry and so forth. Step 1: frighten, step 2: sell protection, step 3: profit. Not saying there aren't risks out there, jus…
Those are just the first two things from the top of my head that IMO rightly took great effort to be taken seriously by the mainstream (developers and consumers alike).
Also I disagree with the "Uncertainty & Doubt" part of FUD. Security researchers are generally extremely clear about what exactly the issues and risks are, with few exceptions when required for responsible disclosure.