Malware researcher Dancho Danchev gone missing since August
zdnet.com
zdnet.com
Perhaps someone at ZDNet re-saved them. If that is the case, they should release the originals.
I tried to search for this list online but I couldn't find it (maybe it is not available yet). The article doesn't say anything about the official situation. It will be great if anyone can provide some official information.
Dancho Danchev, an expert on cybersecurity, is placed in a psychiatric hospital in Bulgaria. The information was confirmed by two sources of "Dnevnik", although the hospital refused to comment.
[...]
[...]
[...] according to reliable source of Dnevnik he was placed in a Bulgarian psychiatric hospital since December 11.
So the question is, who has the key? It seems like if anyone has it, Ryan Naraine should. But if he did, his post would be quite different.
If you count the wires it seems right until you notice that the hacked up blue and white wires are not going to the lighting device at all. Or where the power (phase/neutral) are coming from. They go out of the frame to the left, instead.
I'm not sure what I'm looking at, but it looks like something is in the wall that requires power.
A couple of things come to mind:
- The man might be paranoid and mistook sloppy electrical work for evidence of ... something funny? A threat? I tend to think this is unlikely, as he's a security researcher and probably pretty well versed in these things. If he found a bug, taking a picture of it wouldn't mean anything.
- He's being extremely careful and photographed something that would only mean something to someone specific.
- The two wires that are kludged together seem to go into the wall. The white side is taped to what looks like standard romex, which seems to be where the phase/neutral for the lighting fixture comes from, but those wires travel outside of the frame to who knows where.
- The blue wire that's exposed doesn't look like CAT-5, but the color of the shielding is the same color as some bulk CAT-5 used in construction, though joining the wires under that blue tape seems like a really bad way to connect two exposed ends. I'm leaning towards it not being data cable, but being simple copper wire. Which, yes, could carry data.
- It's unlikely that the images contain information that would be easily deciphered. It's an in-case-of-emergency-break-glass message and it's not explicit as to what these images mean. It's probably intentional.
Anyway, fascinating story and I really hope this guy stays safe. Espionage and cyber crime are huge industries full of all sorts of bad actors.
* Wires coming through the wall are mains voltage. * Exposed wire is ground, the other two are active and neutral. They connect to two white wires. * These two active and neutral wires are connected to two white wires running into the transformer at the left of the photo (although you can't tell whether anything else is connected left of there). * A black double-insulated wire comes out of the transformer, and a brown and blue wire come out of the double insulation. * The brown and blue wires go into the first connector box, which connects via the black double wire to the second connector box. * Two white double wires come out of the second connector box, one going to each light.
GTV seems like it was a transformer manufacturer - it had a US trademark on the name for manufacturing many things until 2008, including for "electric transformers for lighting lamps".
One weird thing: the transformer purports to be a step-down transformer, but the black cable with blue and brown wires (standard colours for mains active and neutral) connects to the low voltage end, when it is probably supposed to connect to the mains end. It is almost as if the step-down transformer is being used as a step-up transformer. The transformer ratio is between 220V/11.6V and 240V/11.6V - so about 20. 240V*20 = 4800V.
If it was configured to produce 4800V on an easily accessible light, perhaps he is trying to say that someone was trying to electrocute him.
Update: I found this, which I think is a more recent model of a similar transformer, from the same manufacturer: http://gemini-technology.en.alibaba.com/productshowimg/30345... - this seems to confirm that the black double insulated wire is supposed to be the 240V input, not the low voltage output.
I don't know if that's helpful, but it's good to understand all of the details; thanks for your analysis, elbrodeur.
... Or, they could just be a photos of a shoddy light fixture installation.
He would be far from the first geek to be overly paranoid.
You're right, it is of course possible that something is getting overanalyzed as we geeks are prone to do, but in the face of what is possibly a bad situation it's worth considering the worst case scenario.
The full text of the image once rotated reads:
ELECTRONIC TRANSFORMER MODEL: TE-60
(20-60W) PRI: 220-240V, 50Hz, CosΦ=0,99 SEC: 11,6V, max. 4.9A Ta: max. 50°C, Tc: max. 85°C
GTV (R)
Dimmable EMC Approved Surge Protection Overload Protection Short Circuit Protection
Symbols: CE, double insulated, don't throw away, and some I don't know.
I can't find it on Google, though.
Now if he cracked open the transformer and found a transmitter hidden inside - then it might get interesting...
If I was going to bug someone for a long time, I would not run new wires. I would piggyback off of some other low power device.
He could have gone searching after they removed everything, and looked for something that was spliced.
On the other hand, I would not bug a bathroom. That seems like the worst place to bug.
-He claims a particular LEO is after him for pro-western views. This is the hardest hit to his credibility. If he said that botnet authors came after him for outing them, that might be plausible. The Belgian government does not hunt and 'disappear' pro-western people.
-There is no stego in this image like some have suggested. If it was in a letter, there is no data to be read. If it did not come from a latter, it was taken recently, according to the metadata. Also, if he is making direct accusations, he is not hiding information. Either the whole message would be cryptic, or none of it. If he isn't afraid to name the guy, he wouldn't be afraid to plainly state that he found a recording device or whatever else.
-He acts like the image has a smoking gun, and it does not.
-He has never had a real, credible job in the industry. See his LinkedIn: http://nl.linkedin.com/in/danchodanchev It's either blogging, or "secret companies". And astalavista, which was warez/script kid forums and stuff.
-His blog is completely full of "cyber jihad" research and discussion of "cyber terrorist" nonsense. http://ddanchev.blogspot.com/
The rest of what you said makes sense, and it is possible that this is a script kid trying to make a name for himself - I would be very weary about making that assumption though without more serious evidence.
I met him in September in a meeting for international law enforcement. He was lecturing.
I agree, it is worth looking into until there is real evidence either way. Hopefully he will come forward. Someone on twitter did say they heard from him on Dec 15th and he was fine.
My experience with these "independent security professionals" who are heavy on certification alphabet soup/government acronyms, and lacking in real credible work history, is that they are mostly playing "fake it until you make it". This especially applies to bloggers and those who heavily use terms like "cyber warfare" and "cyber terrorism". InfoSec is full of insecure charlatans who are broke or homeless and always making up outrageous nonsense.
There's no evidence to suggest otherwise at this point in time. The pictures don't suggest anything to me and he's perfectly capable of not answering the phone, email, or instant messages.
I hope he is ok, both physically and mentally.