... Or, they could just be a photos of a shoddy light fixture installation.
... Or, they could just be a photos of a shoddy light fixture installation.
He would be far from the first geek to be overly paranoid.
You're right, it is of course possible that something is getting overanalyzed as we geeks are prone to do, but in the face of what is possibly a bad situation it's worth considering the worst case scenario.
The full text of the image once rotated reads:
ELECTRONIC TRANSFORMER MODEL: TE-60
(20-60W) PRI: 220-240V, 50Hz, CosΦ=0,99 SEC: 11,6V, max. 4.9A Ta: max. 50°C, Tc: max. 85°C
GTV (R)
Dimmable EMC Approved Surge Protection Overload Protection Short Circuit Protection
Symbols: CE, double insulated, don't throw away, and some I don't know.
I can't find it on Google, though.
Now if he cracked open the transformer and found a transmitter hidden inside - then it might get interesting...
If I was going to bug someone for a long time, I would not run new wires. I would piggyback off of some other low power device.
He could have gone searching after they removed everything, and looked for something that was spliced.
On the other hand, I would not bug a bathroom. That seems like the worst place to bug.
-He claims a particular LEO is after him for pro-western views. This is the hardest hit to his credibility. If he said that botnet authors came after him for outing them, that might be plausible. The Belgian government does not hunt and 'disappear' pro-western people.
-There is no stego in this image like some have suggested. If it was in a letter, there is no data to be read. If it did not come from a latter, it was taken recently, according to the metadata. Also, if he is making direct accusations, he is not hiding information. Either the whole message would be cryptic, or none of it. If he isn't afraid to name the guy, he wouldn't be afraid to plainly state that he found a recording device or whatever else.
-He acts like the image has a smoking gun, and it does not.
-He has never had a real, credible job in the industry. See his LinkedIn: http://nl.linkedin.com/in/danchodanchev It's either blogging, or "secret companies". And astalavista, which was warez/script kid forums and stuff.
-His blog is completely full of "cyber jihad" research and discussion of "cyber terrorist" nonsense. http://ddanchev.blogspot.com/
The rest of what you said makes sense, and it is possible that this is a script kid trying to make a name for himself - I would be very weary about making that assumption though without more serious evidence.
I met him in September in a meeting for international law enforcement. He was lecturing.
I agree, it is worth looking into until there is real evidence either way. Hopefully he will come forward. Someone on twitter did say they heard from him on Dec 15th and he was fine.
My experience with these "independent security professionals" who are heavy on certification alphabet soup/government acronyms, and lacking in real credible work history, is that they are mostly playing "fake it until you make it". This especially applies to bloggers and those who heavily use terms like "cyber warfare" and "cyber terrorism". InfoSec is full of insecure charlatans who are broke or homeless and always making up outrageous nonsense.