Then PayPal has the data and LE can follow the trail. Because it's about LE being able to tell who actually bought the certificate, telling me end users can't do that is kinda moving the goalposts.
Q2: Can't the bad guys just buy a pre-paid debit card with cash if they're that desperate to cover their tracks?