I arrive at the opposite conclusion from reading that. Someone smart enough to work in black hat security should know how fucking illegal CP is, how aggressively its investigated, and know not to flagrantly talk about it on an irc channel and host it to randos online. At the very least they would use tor and figure it out for themselves.
Speaking as someone who lived in a place that would boil dissidents alive in the 00's: That's the most beautiful part of this.
If you know anything about downloading hugely illegal material you will keep your mouth shut because the claims there are completely laughable, but you don't want to admit you've been downloading hugely illegal material that would get you jailed/killed.
To the average person it sounds reasonable because they are an idiot.
To anyone with half a brain even downloading the pdf without doing it through tor, copying it to an air gapped machine, and reading it there is such a huge breach of security you wouldn't be out of prison if you ever did it.
So your argument is that the entire thing is faked? Faked so incredibly well that it will withstand expert analysis at trial? That they faked years of activity (down to the inode level of the filesystem) by this guy and didn't make a single mistake? Because his defense team will tear that evidence apart and will find that mistake if it's there (e.g. any inode activity during a time he has an alibi... very easy to find).
And that you find that more believable than that someone could just happen to be both a security expert and a pedophile?
Do you realize he wasn't caught because of his security lapses? The found the VM because they raided his house for a separate matter. Every indication is that, with the exception of using a password he stored on his phone (which, read the indictment, he clearly realized during the interrogation that he had made a mistake), the government would have never found this VM of his.
He did take the steps you suggest, and it didn't matter, because they raided his house, and he made a single, and easily understandable mistake: he stored the password he used for the VM somewhere where someone could access it digitally. If he had just memorized the password, they would have very likely never broken that encryption.
> Faked so incredibly well that it will withstand expert analysis at trial? That they faked years of activity (down to the inode level of the filesystem) by this guy and didn't make a single mistake?
At this point, we don't know that it will. That's making the argument out to be stronger than it is.
You certainly wouldn't want that guy in charge of doing anything covert! Is it trying to say he used his real name in IRC too (or is that interpretation for the file)!?
News flash: people who are skilled in one area often are not skilled in others, and people who show good judgement in their professional life do not always show it their personal life.
It should also be noted that he did take precautions, many of them, and the VM was only found after they seized his computer for a separate matter. Without that there is no indication they would have ever found it.