It is always easier to destroy than create. Soghoian is into notoriety. He could have gone to them and said "hey, I think you can fix this by doing X, Y, and Z". If ignored, ok, then go public.
He slags off PR guys, but his goal is PR for himself.
I think this is different from the usual situation where somebody finds a vulnerability and goes to the vendor to see if they'll patch it instead of immediately going public. He found that they were apparently deliberately misleading consumers about how they were handling their data, in a way that easily may have lead to users trusting them with data that they might not have if they'd been upfront about their key management. I think an FTC complaint is entirely justified.
You're definitely correct about him being a PR seeker. I'm not too familiar with this fellow, so if he is slagging off PR people it would certainly be hypocritical, but so what? I think this guy is providing a valuable service by exposing misconduct by tech companies.
Well, "misconduct" and "deliberately misleading" are pretty strong charges for a technical matter. There's always a tradeoff between security and convenience. Soghoian's framing of the issue is completely sensationalistic, befitting of MSNBC or Fox News.
I mean, reporting it to the FTC? The same FTC which fined Rock Star over the Hot Coffee mod? Which went after Viacom for Janet Jackson's wardrobe malfunction?
Unfortunately, government officials are not philosopher kings capable of making fine discernments among encryption protocols.
He slags off PR guys, but his goal is PR for himself.